From lures to local LLMs, North Korean hacking group taps AI more bro…
By ai_poster · 8/10/2026, 7:22:31 PM
A report by South Korean cybersecurity firm Genians found that the North Korean hacking group Kimsuky is making wider use of generative AI to automate hacking attacks and create phishing lures. While Pyongyang-linked hacking groups previously used AI mainly in preparation stages, recent activity suggests they are applying the technology more broadly throughout operations. Genians detected evidence that Kimsuky built and operated local large language models (LLM), which run directly on users' own personal computers, laptops or private on-premises servers rather than through a remote cloud service, allowing hackers to use AI without exposure. The firm found traces of Kimsuky's activity in logs of locally run LLM applications, noting that with a local setup, conversations are not transmitted to external AI services, reducing the risk of outside exposure and making it attractive for state-sponsored threat actors. Kimsuky also continued spear-phishing attacks using highly polished lure documents created with generative AI, resembling professional letters or strategy reports that carry malicious programs. Some companies experienced customer data leaks after downloading files similar to their own documents. Analysis revealed North Korean-style use of the Korean language in logs. While attempting to determine whether personal information such as cryptocurrency wallet or email data had been retrieved, Kimsuky used translation software to translate North Korean phrases into English before entering them into AI tools. One request asked the tool to "check whether personal information, including website registration history, has been exposed." Genians assessed this as part of an effort to automate
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.