Kimsuky Leverages Local AI for Sophisticated Crypto Hacking Campaign
The North Korean hacker group Kimsuky has been using local artificial intelligence environments to carry out attacks on cryptocurrency and financial services companies.
According to a report by Genians, a South Korean cybersecurity firm, Kimsuky built and operated three local large language model (LLM) environments using the platforms Ollama, GPT4All, and Msty. These tools allow for fully offline operation and support retrieval-augmented generation, enabling attackers to run queries without sending data to external cloud services.
The group also collected libraries and frameworks to integrate language models into custom software, along with the Cursor programming assistant and speech-to-text tools. This activity focuses on incorporating open-source AI models into malware development, data analysis, and attack automation.
Kimsuky continues to use generative AI to produce high-quality phishing documents thematically focused on digital assets, investment strategies, and fintech services. Some of these documents imitated materials from a Korean AI-powered investment platform, using natural language, consistent professional formatting, and design elements typical of AI-generated content.
In 2025, North Korean hackers stole the equivalent of $2.02 billion in cryptocurrencies, including $1.5 billion taken from the Bybit exchange. This highlights the increasing sophistication of Kimsuky's attacks and their ability to evade detection.