A North Korea-linked hacking group, Kimsuky, has been using artificial intelligence tools, including local large language model (LLM) environments, to advance its cyberattack operations, according to a new report by Genians Security Center.
Genians found indications that Kimsuky, a cyber threat group known to operate under North Korea’s Reconnaissance General Bureau, built and operated local LLM environments using Ollama, GPT4All, and Msty.
Running AI models locally can prevent conversation data from being transmitted to external AI services, reducing the risk of external exposure. Traces showed the tools were not merely downloaded, but were installed and executed, suggesting the group compared and evaluated different approaches to running AI models locally. Genians also identified signs of the group experimenting with retrieval-augmented generation (RAG) and Cursor.
The campaign, tracked by Genians as “Operation GitPower,” typically begins with malicious LNK files inside ZIP archives. When a user opens the LNK file, it quietly runs obfuscated commands that trigger the execution of an embedded PowerShell loader.
Genians also found that some virtual assets and finance documents used as lures were assessed to have been created using generative AI. These documents were notably polished, using natural language and formatting resembling real business materials, making them more convincing and increasing the likelihood that users would trust and open the malicious files.

The group also collected software libraries and other components associated with AI development, according to the report, and used speech-to-text software, including OpenAI’s Whisper, to automatically transcribe audio recordings. It also stored encrypted AsyncRAT malware disguised as image files in public GitHub repositories.
Genians identified several indicators exhibiting North Korea-linked characteristics, including Korean spelling patterns, the term “Arirang,” references associated with North Korean devices, a Chinese-language WPS Office environment, and the use of Astrill VPN.
The firm recommended strengthening behavior-based endpoint detection and response (EDR) and threat hunting, including detection of suspicious LNK files, hidden PowerShell activity, unusually long command-line arguments, scheduled tasks and unexpected access to GitHub’s raw content services.
Genians previously documented a July 2025 campaign in which attackers used ChatGPT to generate a deepfake image resembling a South Korean military agency ID card and incorporated it into a spear-phishing attack targeting defense-related personnel.
The findings come amid growing evidence of North Korean-linked actors misusing AI. An Anthropic threat intelligence report published in August 2025 found that North Korean IT workers had used AI to create highly manipulated virtual identities, complete technical assessments and carry out work after being hired.
In a joint statement with the United States and Japan, South Korea’s Foreign Ministry said North Korean IT workers use false identities and locations, including by leveraging AI tools, to disguise themselves.
The findings come amid growing evidence of North Korean-linked actors misusing AI. Genians cited an Anthropic threat intelligence report published in August 2025, which found that North Korean IT workers had used AI to create highly manipulated virtual identities, complete technical assessments and carry out work after being hired.
South Korea’s Foreign Ministry has also warned that North Korean IT workers use AI tools alongside false identities and locations to disguise themselves. Separately, Genians previously documented a July 2025 campaign in which attackers used ChatGPT to generate a deepfake image resembling a South Korean military agency ID card and incorporated it into a spear-phishing attack targeting defense-related personnel.
Also Read: US State Dept Launches Bureau of Emerging Threats with Focus on AI






