A North Korean hacking group, known as Kimsuky, has developed large language model tools and collected software to help automate cyberattacks, analyze stolen material, and produce more convincing phishing campaigns, according to a report by a South Korean cybersecurity firm, Genians.
Cybersecurity Threats
The report found that Kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All, and Msty, alongside document search technology known as retrieval augmented generation (RAG). These tools could allow operators to process documents without sending sensitive information to outside AI services.
Genians also found AI agent development frameworks, speech-to-text software, and Cursor, an AI-assisted coding tool, on infrastructure linked to the campaign. The findings suggest Kimsuky is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis, and attack automation.
The company’s findings could not be independently verified. North Korea has for years used state-linked cyber units for espionage, financial theft, and revenue generation, according to U.S. and South Korean authorities, as well as cybersecurity experts.
Original reporting: Appleton, WI News Feed (HLL/CB) — read the source article.