
Kimsuky built three offline AI environments using Ollama and GPT4All, avoiding cloud logs. The group targets crypto firms with AI-generated phishing documents.
Alpha Score of 67 reflects moderate overall profile with strong momentum, strong value, weak quality, moderate sentiment.
A hacker group tied to the North Korean state is running artificial intelligence models entirely offline to evade detection while targeting cryptocurrency companies and financial services. The finding, published by South Korean cybersecurity firm Genians, offers a look at how state-backed attackers are adapting their tradecraft.
Kimsuky built and operated three local large language model environments using the platforms Ollama, GPT4All, and Msty, the report said. These tools function without an internet connection and support retrieval-augmented generation, which lets attackers query data without sending anything to cloud servers. That leaves no log on a third-party provider's infrastructure.
The group also collected libraries and frameworks needed to embed language models into custom software, along with the Cursor programming assistant and speech-to-text tools. Genians said the activity points to a shift from testing the technology to using it for malware development, data analysis, and attack automation.
"This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off AI experimentation and is continuously preparing to integrate the technology into real attack capabilities," the firm said.
Separately, Genians found that Kimsuky continues to use generative AI to produce phishing documents about digital assets, investment strategies, and fintech services. Some of those documents imitated materials from a Korean AI-powered investment platform, using natural language and professional formatting typical of AI-generated content.
Chainalysis data shows North Korean hackers stole the equivalent of $2.02 billion in cryptocurrencies during 2025, including the $1.5 billion taken from the Bybit exchange.
NEAR Protocol co-founder Illia Polosukhin recently warned that AI is accelerating attackers' ability to find software vulnerabilities at a speed that traditional security systems cannot match. The $100 million exploit targeting Bitcoin's Coldcard hardware wallets is suspected to stem from a vulnerability discovered through AI, according to security researchers.
The Genians report adds to a growing body of evidence that state-backed hacking groups are embedding AI tools into their workflows. Running models locally removes the risk of exposing queries to cloud providers or leaving a trail that investigators might trace. For crypto firms, the threat model now includes attackers who can automate parts of the reconnaissance, document forgery, and code analysis pipeline without relying on external services.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.