North Korea’s Kimsuky Hacking Group Built Its Own Local AI Tools to Power Cyberattacks
Genians found Kimsuky running AI tools locally to automate cyberattacks and craft more convincing phishing lures.

South Korean cybersecurity firm Genians said Monday that North Korean-linked hacking group Kimsuky has built and deployed local AI tools to automate cyberattacks, analyse stolen data, and create more convincing phishing campaigns.
The firm said it traced the tools to Kimsuky-linked infrastructure, a group the U.S. Treasury has already sanctioned in 2023 for gathering intelligence for Pyongyang. The findings show Kimsuky is expanding its AI capabilities beyond public chatbots to infrastructure it controls directly.
From Borrowed Chatbots to a Self-Hosted AI Stack
According to Reuters, Genians’ findings suggest Kimsuky is moving beyond using generative AI merely to write phishing lures, and is instead building the capacity to weave existing models more deeply into its hacking operations, including malware development.
That distinction is the real story here: a hacking group asking a public chatbot to draft a convincing email is a workflow shortcut, but standing up local infrastructure to run, manage, and chain AI systems together is closer to building custom tooling.
Reuters also noted that Genians uncovered finance and cryptocurrency-themed decoy documents that appeared AI-generated and were designed to resemble legitimate investment reports to tempt specific targets.
A South Korean Firm Watching a South Korean Target List
Genians’ own research found that Kimsuky continues targeting foreign diplomatic missions, South Korea’s military and security sectors, and virtual asset companies.
The group uses Git based repositories to manage its operations and distribute encrypted AsyncRAT payloads, per the source.
The findings suggest Kimsuky’s AI development remains focused on the strategic targets it has pursued for years rather than serving as a general upgrade.
This fits a broader pattern of Pyongyang-backed attacks, including the recent breach of the Axios library by North Korean hackers, raising concerns over software supply chain attacks and cryptocurrency theft.
Genians also found Korean language artifacts linked to the campaign’s infrastructure, further connecting the tools to North Korean operators.
Local AI Isn’t Just Convenience, It’s Operational Security
What makes this disclosure notable isn’t that a state-linked hacking group is using AI, but that Kimsuky is moving to local tools instead of public services like ChatGPT, which it reportedly used last year to create a fake South Korean military ID.
Public AI services log queries and can block or flag suspicious requests, while local tools let operators process sensitive data without sending it to outside providers.
That’s a meaningful operational upgrade: it removes the single biggest way defenders have caught AI-assisted attacks so far, a hacker’s own prompts leaving a trail on someone else’s server.
If these state-linked groups increasingly run their own AI models instead of using commercial ones, monitoring major AI platforms for suspicious activity will very likely become less effective as these threats grow.


