A North Korean-linked hacking group is developing its own artificial intelligence tools to make cyberattacks more automated, analyse stolen information and create more convincing phishing campaigns, according to South Korean cybersecurity company Genians.

Genians said it found evidence that the Kimsuky hacking group had installed and used several tools for running AI models locally. These included Ollama, GPT4All and Msty, along with retrieval-augmented generation (RAG) technology that can help AI systems search and work with large collections of documents.

Running AI models locally could allow the attackers to analyse sensitive or stolen information without sending it to external AI services. This could give them more control over the data and reduce the risk of exposing their activities to third-party AI providers.

The security firm also discovered AI agent development frameworks, speech-to-text software and Cursor, an AI-powered coding tool, on infrastructure connected to the campaign.

According to Genians, the findings indicate that Kimsuky may be moving beyond simply using generative AI to write phishing messages. The group appears to be building the ability to integrate existing AI models into different parts of its operations, including malware development, stolen-data analysis and attack automation.

Genians also identified finance and cryptocurrency-themed documents that appeared to have been created using AI. The documents were designed to look like genuine investment reports and other workplace materials, potentially making them more convincing to targeted victims.


Buy ExpressVPN with PayPal or Credit Card
Advertisement
READ
Google Warns Hackers Are Targeting Major U.S. Financial Firms With Phone Scams