3 min Security

North Korean hackers build an AI environment for cyberattacks

North Korean hackers build an AI environment for cyberattacks

The North Korean hacker group KIMSUKY appears to be seeking to integrate AI more systematically into its attack infrastructure. Researchers discovered various local AI tools, agent frameworks, and document analysis technology. This allows the group to deploy AI without sending data to external services.

This is according to research by the South Korean cybersecurity firm Genians, Reuters reports. The researchers link the discovered infrastructure to Kimsuky, a group associated with the North Korean government.

Particularly notable is the collection of software found on the systems. This includes Ollama, GPT4All, and Msty, which allow large language models to be run and managed locally. Genians also found technology for retrieval-augmented generation (RAG). This enables a language model to use information from its own document collection when answering questions or performing tasks.

Such a local environment offers attackers a significant advantage. Stolen documents and other sensitive data do not need to be sent to an external AI service for analysis by a model. Processing can take place within the organization’s own infrastructure.

From phishing to automation

KIMSUKY has long been associated with the use of generative AI for phishing. However, according to Genians, the new findings point to a broader application. The group appears to be seeking to integrate existing AI models into areas such as malware development, data analysis of stolen data, and attack automation.

This is consistent with other software the researchers discovered. For example, they developed frameworks for developing AI agents, speech-to-text software, and Cursor, a programming environment that allows AI to assist with writing and modifying code.

This combination suggests that KIMSUKY is experimenting with an AI stack capable of supporting multiple stages of a cyber operation. For example, rather than merely generating text for phishing emails, models could process large amounts of stolen information or assist with programming tasks.

AI makes decoy documents more credible

AI also appears to continue being used for social engineering. Genians found documents on financial topics and cryptocurrency that were likely created using generative AI. They were designed to look like investment reports and other documents that might normally circulate within organizations.

Such files can be used as bait to trick victims into opening a document or engaging further with the attacker.

Genians emphasizes that the findings indicate that KIMSUKY is looking beyond the occasional use of public generative AI services. According to the researchers, the group is building capacity to integrate AI models into malware development, data analysis, and automated attacks. Reuters was unable to independently verify Genians’ findings.

KIMSUKY has been on governments’ radar for some time. The U.S. Department of the Treasury imposed sanctions on the group in 2023, describing it as a cyber-espionage group directed by the North Korean government. According to U.S. and South Korean authorities, North Korea deploys such cyber units for espionage, financial theft, and revenue generation.