According to the latest report released by the South Korean cybersecurity company Genians on August 10, the hacker group Kimsuky, under the Reconnaissance General Bureau of North Korea, is researching how to gradually incorporate technologies such as generative artificial intelligence (AI) and large language models (LLM) into their cyber attacks.
Genians, while tracking the infrastructure related to Kimsuky attacks, discovered that the organization is using tools such as Ollama, GPT4All, and Msty to allow AI models to run directly on their own computers or servers. This means they can use AI to search, organize, and analyze data on hand without relying on external AI services, thereby reducing traces of data leaks and increasing the stealthiness of their attacks.
Furthermore, Genians also found AI agent development frameworks, speech-to-text (STT) tools, and AI program development tools like Cursor. This indicates that Kimsuky is not only focusing on creating phishing emails using AI, but also accumulating the capability to apply AI for data analysis, information extraction, malicious program development, and attack automation.
AI may make the bait for cyber attacks more realistic. Genians discovered that Kimsuky has recently used bait documents on topics like cryptocurrency, financial investments, and game development, some of which appear to be created using generative AI to make the documents look more like legitimate investment reports or work data, increasing the likelihood of victims being deceived.
However, AI is not the only tool Kimsuky relies on. Genians also found that the organization continues to target foreign diplomatic missions, as well as fields like military, security, and virtual assets, using Git-based repositories like GitHub as attack infrastructure, including delivering encrypted AsyncRAT malware. The attacks also involve common tools like LNK files and PowerShell, indicating that Kimsuky is integrating AI with existing hacking techniques to establish a more comprehensive attack process.
For the average internet user, the most significant change may be that in the future, phishing emails and malicious files may no longer be as easy to identify based on typos, strange tones, or rough layouts.
Genians stated that Kimsuky is currently in the phase of accumulating technology and capabilities, exploring how to integrate AI into their overall attack operations, with no evidence showing they have trained new AI models themselves.
Nevertheless, this remains a warning signal. The real concern is not just autonomous AI entities potentially launching cyber attacks, but also humans learning to leverage AI to enhance their own capabilities. In July of this year, OpenAI disclosed an AI agent-related security incident and warned that as AI model autonomy improves, the threat of using AI to conduct cyber attacks may increasingly grow.
For hackers, AI can make cyber attacks faster, more precise, and possibly harder to detect; and for global cybersecurity, the real challenge lies in AI potentially serving as both a defense tool and as an ‘amplifier of capabilities’ in the hands of attackers.
