Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
North Korean hacking group Kimsuky develops AI tools to automate cyberattacks, South Korean firm reports
00

North Korean hacking group Kimsuky develops AI tools to automate cyberattacks, South Korean firm reports

Aug 10, 2026

South Korean cybersecurity firm Genians reports that the North Korean state-backed hacking group Kimsuky is developing local large language model tools and collecting software to automate cyberattacks. Kimsuky has deployed offline tools like Ollama, GPT4All, and Msty to process stolen data securely, alongside OpenAI Whisper archives to transcribe intercepted audio. The group also uses AI-generated decoy documents to target diplomatic, military, and financial entities globally.

Kimsuky AI tool development

  • ▪The South Korean cybersecurity firm Genians reported on August 10, 2026, that the North Korean hacking group Kimsuky has built local large language model tools and collected software to automate cyberattacks.
  • ▪Genians identified AI agent development frameworks, .NET and C# AI-development packages, and the AI-assisted coding tool Cursor on infrastructure linked to Kimsuky's campaign.
  • ▪Genians reported that Kimsuky is transitioning from using generative AI solely for phishing lures to integrating existing AI models into malware development, data analysis, and attack automation.

Local LLM deployment

  • ▪Genians discovered that Kimsuky set up tools to run and manage AI models locally, including Ollama, GPT4All, and Msty, to process documents without sending sensitive information to outside AI services.
  • ▪Genians found a GPT4All database named localdocs_v3.db on Kimsuky's infrastructure, indicating the configuration of a retrieval-augmented generation environment to search and query stolen document collections.

Speech-to-text transcription capabilities

  • ▪Genians discovered OpenAI Whisper-related archives, including faster-whisper.7z and whisper.7z, alongside Korean-language training materials on Kimsuky's infrastructure for extracting text from audio files.
  • ▪Genians assessed that Kimsuky is in a research and capability-acquisition phase for speech-to-text tools, with no evidence that the transcription tooling has been operationally deployed against victims.

AI-generated phishing documents

  • ▪Genians reported that Kimsuky has used AI-generated, highly polished finance and cryptocurrency-themed decoy documents designed to resemble legitimate investment reports in its spear-phishing campaigns since 2026.
  • ▪Kimsuky's Operation GitPower targets foreign diplomatic missions, military and security organizations, policy and academic communities, and virtual-asset-related entities using malicious LNK files disguised as legitimate correspondence.

North Korean cyber espionage

  • ▪The U.S. Treasury sanctioned Kimsuky in 2023 as a North Korean government-controlled cyber-espionage group that gathers intelligence to support Pyongyang's strategic objectives.
  • ▪According to British blockchain analytics firm Elliptic, North Korean hackers stole more than $2 billion worth of cryptocurrency during the first nine months of 2025.

8 sources

Japantimes
North Korean hacking group builds AI tools for cyberattacks, report says
View source article
Gbhackers
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
View source article
Digit
Hackers reportedly building ChatGPT-like AI tools to automate cyberattacks, make them more convincing
View source article
Seekingalpha
North Korean hackers build AI tools for cyberattacks: report (BUG:NASDAQ) | Seeking Alpha
View source article
Devdiscourse
North Korean Hackers Advance with AI-Enhanced Cyber Tools | Technology
View source article

Featured stories

View more in Phishing attacks

Google announces Gemini 4 Argon in limited release to cybersecurity partners

Sep 30, 2026 · 12 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Kevin Mandia's cybersecurity startup Armadin raises $255.5 million at $2.5 billion valuation

Oct 1, 2026 · 4 sources

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources

Story comments

Loading comments…

Related entities

South KoreaNorth Korea

Topics

Phishing attacksAI cybersecurityAI misinformation & deepfakesAI tools & productsAI security

Featured stories

View more in Phishing attacks

Google announces Gemini 4 Argon in limited release to cybersecurity partners

Sep 30, 2026 · 12 sources

Anthropic releases Claude Sonnet 5.5 with 30% speed and cost improvements ahead of planned IPO

Sep 28, 2026 · 6 sources

Kevin Mandia's cybersecurity startup Armadin raises $255.5 million at $2.5 billion valuation

Oct 1, 2026 · 4 sources

OpenAI alerts over 100 organizations about rogue AI agent activity

Oct 1, 2026 · 2 sources