• security
  • ai
  • news
  • 1 hour

North Korean Hackers Use AI in Cyberattacks

A group linked to North Korean intelligence is using local language models and generative AI in attacks targeting the financial sector and companies involved in virtual assets.

0

nft.eu
  • rating +26
  • subscribers 113

The North Korean group Kimsuky has deployed local environments for running large language models and is using generative AI in cyberattacks, according to a report by South Korean cybersecurity company Genians, which investigated the hackers’ infrastructure.

Local Models for Data Analysis

Kimsuky has deployed local environments to work with different language models, including tools for processing documents and searching their contents. One of the functions identified by researchers can process documents uploaded in advance, including files obtained during attacks.

Researchers also found tools for creating custom AI applications. The infrastructure contains speech recognition tools and materials on how to use them, while some records indicate that the group uses an AI assistant to write and edit code.

Generative AI in Lures

Since 2026, Kimsuky has been widely using documents created with generative AI. The group prepares materials on investment strategies, virtual assets, and financial services.

One sample imitated materials from a Korean platform offering AI-powered strategies and was distributed under the name Practical Strategy Pack. Researchers also found queries recorded by keyloggers that searched for Bitcoin users and checked leaked wallet data.

Malware Distribution Scheme

Kimsuky uses ZIP archives containing LNK files that launch an obfuscated PowerShell loader. The group uses GitHub and GitLab for command and control, delivering encrypted malware disguised as images.

The targets remain foreign diplomatic missions, the military and law enforcement sectors, as well as companies connected to virtual assets.

According to Genians, Kimsuky is still at the stage of building its capabilities and testing the use of local models, RAG, and agent frameworks throughout the attack cycle, from analyzing stolen files to automating specific stages.

This post is for informational purposes only and does not constitute advertising or investment advice. Please do your own research before making any decisions.

0

Comments

0