Journalism begins where hype ends

,,

We can only see a short distance ahead, but we can see plenty there that needs to be done.” "

—Alan Turing

North Korean Hacking: Kimsuky Builds AI Tools Using Local LLMs for Cyberattacks

According to Genians’ latest report, the North Korea-linked Kimsuky group is expanding its cyber toolkit with local LLMs, AI-powered transcription and AI-generated phishing lures.
Red warning triangle featuring a hooded hacker and exclamation mark over a blurred background of computer code.
August 10, 2026 03:25 PM IST | Written by Supriya Singh | Edited by Pratima O Pareek

A North Korea-linked hacking group, Kimsuky, has been using artificial intelligence tools, including local large language model (LLM) environments, to advance its cyberattack operations, according to a new report by Genians Security Center.

Genians found indications that Kimsuky, a cyber threat group known to operate under North Korea’s Reconnaissance General Bureau, built and operated local LLM environments using Ollama, GPT4All, and Msty.

Running AI models locally can prevent conversation data from being transmitted to external AI services, reducing the risk of external exposure. Traces showed the tools were not merely downloaded, but were installed and executed, suggesting the group compared and evaluated different approaches to running AI models locally. Genians also identified signs of the group experimenting with retrieval-augmented generation (RAG) and Cursor.

The campaign, tracked by Genians as “Operation GitPower,” typically begins with malicious LNK files inside ZIP archives. When a user opens the LNK file, it quietly runs obfuscated commands that trigger the execution of an embedded PowerShell loader.

Genians also found that some virtual assets and finance documents used as lures were assessed to have been created using generative AI. These documents were notably polished, using natural language and formatting resembling real business materials, making them more convincing and increasing the likelihood that users would trust and open the malicious files.

The group also collected software libraries and other components associated with AI development, according to the report, and used speech-to-text software, including OpenAI’s Whisper, to automatically transcribe audio recordings. It also stored encrypted AsyncRAT malware disguised as image files in public GitHub repositories.

Genians identified several indicators exhibiting North Korea-linked characteristics, including Korean spelling patterns, the term “Arirang,” references associated with North Korean devices, a Chinese-language WPS Office environment, and the use of Astrill VPN.

The firm recommended strengthening behavior-based endpoint detection and response (EDR) and threat hunting, including detection of suspicious LNK files, hidden PowerShell activity, unusually long command-line arguments, scheduled tasks and unexpected access to GitHub’s raw content services.

Genians previously documented a July 2025 campaign in which attackers used ChatGPT to generate a deepfake image resembling a South Korean military agency ID card and incorporated it into a spear-phishing attack targeting defense-related personnel.

The findings come amid growing evidence of North Korean-linked actors misusing AI. An Anthropic threat intelligence report published in August 2025 found that North Korean IT workers had used AI to create highly manipulated virtual identities, complete technical assessments and carry out work after being hired.

In a joint statement with the United States and Japan, South Korea’s Foreign Ministry said North Korean IT workers use false identities and locations, including by leveraging AI tools, to disguise themselves.

The findings come amid growing evidence of North Korean-linked actors misusing AI. Genians cited an Anthropic threat intelligence report published in August 2025, which found that North Korean IT workers had used AI to create highly manipulated virtual identities, complete technical assessments and carry out work after being hired.

South Korea’s Foreign Ministry has also warned that North Korean IT workers use AI tools alongside false identities and locations to disguise themselves. Separately, Genians previously documented a July 2025 campaign in which attackers used ChatGPT to generate a deepfake image resembling a South Korean military agency ID card and incorporated it into a spear-phishing attack targeting defense-related personnel.

Also Read: US State Dept Launches Bureau of Emerging Threats with Focus on AI

Authors

  • AI FrontPage Reporter Supriya Singh

    Supriya Singh is a Reporter at AI FrontPage covering the AI & Education and AI & Jobs beats. She brings six years of print and digital experience, including three years at The Asian Age, where she reported on higher education, Delhi government, and crime. She is based in Delhi-NCR.

    LinkedIn

  • Pratima Pareek, Editor and Co-founder of AI FrontPage

    Pratima O Pareek is an Editor and Co-Founder of AI FrontPage. A gold medalist in Mass Communication and Journalism, she's worked across national and international newsrooms, bringing sharp editorial instincts and a commitment to clarity. She believes in cutting through the noise to deliver stories that actually matter.
    Off the clock, she watches offbeat cinema, follows tennis, and explores new places like a traveler, not a tourist.

    LinkedIn