North Korea-linked hacking group Kimsuky is integrating artificial intelligence directly into its cyber operations, using locally operated AI models to improve phishing campaigns, analyze stolen data, assist malware development, and automate attacks targeting the cryptocurrency and financial industries. South Korean cybersecurity firm Genians says it discovered evidence that the state-backed group has moved beyond simply experimenting with AI and is actively building the infrastructure needed to incorporate the technology into real-world cyberattacks.
The findings are particularly concerning for the crypto industry because Kimsuky is using generative AI to create highly polished phishing documents themed around digital assets, investment strategies, and fintech services. The development comes as North Korean hacking operations continue to generate billions of dollars in stolen cryptocurrency, while AI is making sophisticated cyberattack techniques faster and more accessible.
Kimsuky Builds Its Own Local AI Environment
Rather than relying exclusively on popular cloud-based AI services, Kimsuky appears to be building AI infrastructure that can operate locally.
Genians discovered three local large language model environments using Ollama, GPT4All, and Msty. These platforms allow hackers to run AI models directly on their own computers without sending queries or sensitive information to outside cloud providers.
This provides several advantages for a state-backed hacking organization. Local AI systems can operate offline, reduce dependence on foreign technology companies, and make it more difficult for outside providers to detect how the models are being used.
Kimsuky is also using retrieval-augmented generation, or RAG, which allows AI models to incorporate information from external databases and documents when producing responses.
AI Is Being Integrated Into Malware Development
The hackers aren’t limiting AI to writing emails.
Genians found that Kimsuky has been collecting software libraries and frameworks that allow language models to be embedded into custom applications.
The group has also incorporated Cursor, an AI-powered coding assistant, along with speech-to-text technology into its development environment.
According to researchers, the tools appear to be supporting several areas of Kimsuky’s operations, including malware development, data analysis, and attack automation.
Genians said the activity provides evidence that the hackers are preparing to continuously integrate AI into their offensive capabilities rather than simply conducting isolated experiments.
Crypto Investors Are Being Targeted With AI-Generated Phishing
Cryptocurrency and financial services remain important targets.
Researchers discovered phishing materials created by Kimsuky that focused specifically on digital assets, investment strategies, and fintech products.
Some of the documents closely copied materials associated with a Korean AI-powered investment platform.
The phishing documents contained natural-sounding language, professional formatting, and consistent visual design, potentially making them considerably more convincing than the poorly written scam emails traditionally associated with phishing attacks.
That could make identifying malicious communications increasingly difficult for crypto investors and employees working inside digital asset companies.
North Korea Isn’t Building Its Own AI Models Yet
Despite Kimsuky’s increasing use of artificial intelligence, Genians found no evidence that the group is currently developing frontier AI models from scratch.
Instead, the hackers appear focused on integrating existing open-source AI technologies into their cyber operations.
That distinction is important because it demonstrates how sophisticated AI-enabled cyberattacks no longer necessarily require the enormous computing infrastructure needed to train advanced models.
Hackers can take existing open-source models, operate them locally, customize them for specific tasks, and integrate them directly into malicious software.
North Korean Hackers Stole More Than $2 Billion in Crypto Last Year
North Korea already represents one of the cryptocurrency industry’s most serious cybersecurity threats.
According to Chainalysis data cited by The Block, North Korean hackers stole approximately $2.02 billion in cryptocurrency last year, including the roughly $1.5 billion Bybit hack.
North Korean cyber operations have historically used a wide range of techniques, ranging from relatively simple phishing campaigns to sophisticated social engineering operations and placing North Korean IT workers inside cryptocurrency companies to gain access to sensitive systems.
Previous United Nations reporting estimated that cyberattacks had become a major source of foreign currency for North Korea and helped finance a significant portion of the country’s weapons programs.
AI Could Make Social Engineering Much More Dangerous
One of the biggest threats from AI may not involve discovering complicated software vulnerabilities.
It could simply make social engineering considerably better.
Generative AI allows attackers to produce highly personalized emails, investment reports, resumes, presentations, PDFs, and other documents without the grammatical mistakes or awkward language that traditionally helped victims recognize phishing attempts.
An attacker could potentially collect information about a crypto executive or developer and then use AI to create communications specifically designed around that person’s company, job responsibilities, business relationships, and interests.
For an industry where compromising a single employee can potentially expose private keys or internal systems controlling millions of dollars, more convincing social engineering represents a serious security challenge.
Crypto’s AI Security Arms Race Is Accelerating
The Kimsuky findings arrive during a remarkable stretch of AI-related cybersecurity developments across crypto.
Bitcoin developers have begun using an AI-powered Red Team to scan open-source repositories for vulnerabilities. Researchers have already reported numerous potential security issues.
Meanwhile, recent incidents involving COLDCARD and BTCPay Server have raised concerns about attackers using similar AI capabilities to discover weaknesses before developers can patch them. The recent COLDCARD attacks alone have been linked to potentially more than $100 million in Bitcoin losses.
NEAR Protocol co-founder Illia Polosukhin has warned that AI is accelerating hackers’ ability to discover software vulnerabilities faster than traditional cybersecurity teams can respond.
- Alibaba Backs Singapore’s MetaComp to Scale Hybrid Stablecoin Payments
- Japan Proposes Stricter Crypto Rules Under Securities Law
- Coinbase Secures MiCA Approval, Shifts Headquarters to Luxembourg
- Israel Approves First Shekel-Pegged Stablecoin After Two-Year Pilot
- Animoca Brands, Standard Chartered’s Joint Venture Initiates Stablecoin Licensing Process in Hong Kong
- Russia Confirms Digital Ruble Is Ready for Nationwide Launch as Banks Prepare for September Rollout




















































































































































