Kimsuky Leverages AI in Cyberattacks on Crypto Firms
North Korea's Kimsuky threat actor has been researching ways to use artificial intelligence in its cyberattack operations, including malware development and data analysis. The group, which frequently targets the cryptocurrency and financial sectors, set up local AI environments using Ollama, GPT4All, and Msty to prevent conversation data from being transmitted to external AI services.
The investigation found that Kimsuky collected libraries and frameworks that can integrate artificial intelligence into software, including LLaMaSharp, Microsoft Semantic Kernel, and Microsoft Agents AI. The group also gathered files related to Whisper and faster-whisper speech-to-text tools, which could be used to process and analyze stolen or compromised data.
This development raises concerns about the increasing sophistication of North Korea-linked attackers in using artificial intelligence to enhance their attack capabilities. In 2026, North Korea-linked attackers were responsible for over half of the cryptocurrency stolen, with a total loss of $609 million.