A North Korean-linked hacking group has reportedly built a set of tools around large language models and collected software capable of automating cyberattacks, analysing stolen information, and producing more convincing phishing campaigns. The findings come from South Korean cybersecurity firm Genians, which has been tracking the group's activities.
Running AI Models Locally, Away From External Servers
According to Genians, the group — known as Kimsuky — has established infrastructure to run and manage AI models locally, rather than relying on external AI services. The setup reportedly includes tools like Ollama, GPT4All, and Msty, along with retrieval-augmented generation (RAG) technology designed for document search.
What makes this significant is that running AI models locally allows operators to process documents and sensitive information without ever sending it to outside AI services — effectively keeping everything within infrastructure they fully control, making it harder to trace or intercept.
The cybersecurity firm also discovered AI agent development frameworks, speech-to-text software, and even Cursor, an AI-assisted coding tool, on infrastructure linked to this campaign. Taken together, these findings suggest Kimsuky may be moving well beyond simply using generative AI to write phishing emails. Genians said the group appears to be actively developing the capability to weave existing AI models directly into malware development, data analysis, and attack automation — essentially using AI across multiple stages of a cyber operation, all while keeping stolen or sensitive data within locally controlled systems.
Fake Finance and Crypto Documents Designed to Deceive
Investigators also found finance and cryptocurrency-themed decoy documents that appeared to have been generated using AI. These materials were designed to closely resemble legitimate investment reports and other workplace documents — a tactic clearly aimed at making deceptive content look more credible and trustworthy to intended targets. The findings suggest AI isn't just being used to write convincing phishing lures anymore; it may also be helping with the broader processing and exploitation of information gathered during these cyber operations. It's worth noting that these findings could not be independently verified beyond Genians' own research.
A Longer History of State-Linked Cyber Activity
North Korea has, for years, used state-linked cyber units for espionage, financial theft, and revenue generation, according to both U.S. and South Korean authorities, as well as independent cybersecurity experts. This latest development points toward a potential next step — integrating artificial intelligence more directly into these existing cyber capabilities, with locally deployed AI models offering tools for information analysis, malicious software development, and attack automation.
If accurate, this shift would represent something notable: moving away from using generative AI primarily to create content, and toward embedding the technology more deeply into the actual technical infrastructure that supports cyber operations from start to finish.
FAQs
Q1. What AI tools did Kimsuky reportedly use to support its cyber operations?
The group reportedly used locally run AI models including Ollama, GPT4All, and Msty, along with retrieval-augmented generation technology, AI agent frameworks, and the AI coding tool Cursor.
Q2. Why does running AI models locally matter for cybercriminals?
Running AI models locally allows operators to process sensitive or stolen information without sending it to external AI services, keeping data within infrastructure they fully control.
Q3. What kind of decoy documents were found linked to this campaign?
Investigators found finance and cryptocurrency-themed decoy documents that appeared AI-generated, designed to resemble legitimate investment reports to deceive targets.