This website uses cookies

Read our Privacy policy and Terms of use for more information.

North Korean Hackers Are Building Their Own AI Infrastructure to Automate Cyberattacks

North Korean state-backed hackers have moved well past simply using off-the-shelf AI chatbots for phishing scams, and are now building genuine AI infrastructure of their own specifically to scale their attacks. Kimsuky, a hacking group linked to North Korea's Reconnaissance General Bureau and sanctioned by the U.S. Treasury in 2023, has used AI-generated documents in a "pattern" of spear-phishing attacks since 2026, according to a report from South Korean cybersecurity firm Genians, covered by Al Jazeera.

The group has automated the creation of malicious files disguised as legitimate documents, including research reports and invitations, and to avoid detection, has used open-source tools including Ollama, GPT4All, and Msty to run large language models locally without an internet connection, according to Al Jazeera's reporting on the findings.

Building an Entire Local AI Ecosystem, Not Just Using Public Tools

The most technically significant detail in Genians' findings is the scope of what Kimsuky has actually built. Investigators found evidence the group established local environments to deploy and operate AI models entirely on its own systems, alongside document search technology known as retrieval-augmented generation, or RAG, according to Business Standard's detailed reporting on the discovery. Genians also identified AI agent development frameworks, speech-to-text software, and the AI-assisted coding tool Cursor on infrastructure linked to the campaign, suggesting Kimsuky is moving well beyond generating phishing lures toward genuinely integrating AI across its broader operational toolkit.

The local, offline nature of this setup is strategically deliberate. Running AI models locally rather than through external cloud services lets the group process sensitive documents without ever transmitting them to a third-party AI provider, preserving operational security while still gaining AI-driven capability, according to Genians' analysis cited across multiple outlets covering the report.

A Pattern With a Documented History

This isn't Kimsuky's first documented use of AI for deception. Genians previously found the group used ChatGPT to generate a realistic fake South Korean military ID for a phishing campaign, and Google's cybersecurity firm Mandiant separately warned that North Korean threat actors have used AI-generated deepfakes in fake video calls to deceive cryptocurrency and DeFi targets, according to earlier reporting cited by Business Standard. North Korean hackers were responsible for roughly $643 million in stolen cryptocurrency during just the first half of 2026, or 66% of all crypto hacking losses globally, according to blockchain intelligence firm TRM Labs, cited in Cryptopolitan's reporting on the group's broader financial impact.

Jenny Town, a senior fellow at the Stimson Center, offered a measured assessment of the development. "North Korea's hackers and programmers are more than capable of utilising and exploiting various AI tools to enhance their efforts," Town told Al Jazeera. "This is a new reality of all threat actors; North Korea is no exception," a framing worth understanding alongside our broader coverage of Ollama's rapid growth as the platform powering exactly this kind of local, self-hosted AI deployment across both legitimate and malicious use cases.

Why This Matters for Business

This report is worth understanding for any business, particularly in finance, defense, diplomacy, or academia, given those are Kimsuky's documented target sectors. The sophistication of these AI-generated phishing documents means traditional employee training focused on spotting poor grammar or generic phrasing is becoming genuinely less reliable as a defense, since AI-generated lures can now closely replicate authentic corporate tone and formatting.

For security teams, this development reinforces that AI-powered threat detection is increasingly necessary to counter AI-powered attacks, since the sophistication gap between human-crafted and AI-generated phishing content is narrowing quickly.

The Fast Version

North Korean state-backed hacking group Kimsuky has built its own local AI infrastructure, including offline large language models and AI agent frameworks, to automate and scale its cyberattacks, according to South Korean cybersecurity firm Genians. The group used AI to generate convincing phishing documents disguised as legitimate research reports and financial materials, targeting military, diplomatic, and academic sectors. North Korean hackers were responsible for 66% of all cryptocurrency hacking losses globally in the first half of 2026, and this AI-driven sophistication marks a significant escalation from earlier, simpler uses of public chatbots for phishing.

Keep Reading

View more
caret-right