The North Korean group Kimsuky has deployed local environments for running large language models and is using generative AI in cyberattacks, according to a report by South Korean cybersecurity company Genians, which investigated the hackers’ infrastructure.
Local Models for Data Analysis
Kimsuky has deployed local environments to work with different language models, including tools for processing documents and searching their contents. One of the functions identified by researchers can process documents uploaded in advance, including files obtained during attacks.
Researchers also found tools for creating custom AI applications. The infrastructure contains speech recognition tools and materials on how to use them, while some records indicate that the group uses an AI assistant to write and edit code.
Generative AI in Lures
Since 2026, Kimsuky has been widely using documents created with generative AI. The group prepares materials on investment strategies, virtual assets, and financial services.
One sample imitated materials from a Korean platform offering AI-powered strategies and was distributed under the name Practical Strategy Pack. Researchers also found queries recorded by keyloggers that searched for Bitcoin users and checked leaked wallet data.
Malware Distribution Scheme
Kimsuky uses ZIP archives containing LNK files that launch an obfuscated PowerShell loader. The group uses GitHub and GitLab for command and control, delivering encrypted malware disguised as images.
The targets remain foreign diplomatic missions, the military and law enforcement sectors, as well as companies connected to virtual assets.
According to Genians, Kimsuky is still at the stage of building its capabilities and testing the use of local models, RAG, and agent frameworks throughout the attack cycle, from analyzing stolen files to automating specific stages.
