North Korean Hackers Leverage Local AI for Crypto Attacks
North Korean hackers linked to Kimsuky have developed three local AI environments to automate attacks on cryptocurrency and financial companies. The group has built environments using Ollama, GPT4All, and Msty, giving them access to AI tools that can run without relying on external cloud services.
The AI systems allow operators to make queries without sending sensitive attack information to third-party providers. Kimsuky also uses these local models for malware development, data analysis, and attack automation. Researchers found libraries and frameworks that can embed language models into custom software, allowing the group to prepare phishing material focused on cryptocurrency, investment strategies, and fintech services.
The group has used generative AI to create polished documents with natural language, consistent formatting, and professional design elements. These materials provide another use for Kimsuky's AI infrastructure beyond coding and data processing. The development of AI-assisted attack infrastructure comes after North Korean hacking groups stole an estimated $2.02 billion in cryptocurrency during 2025.
The Bybit February 2025 attack was the largest contributor to these losses, with over 400,000 Ether and staked Ether worth around $1.5 billion stolen. The FBI attributed the breach to North Korea and identified the actors responsible under its TraderTraitor designation. Bybit has since taken the dispute into a U.S. federal court.