Genian Analyzes North Korea's Kimsuky AI Attack Activities... Advances Cyber Attacks with Local LLM Deployment
Genian (263860) announced on August 10 that an analysis of recent attacks by Kimsuky—known as a hacking organization under North Korea’s Reconnaissance General Bureau—revealed evidence that Kimsuky has been researching techniques to leverage generative artificial intelligence (AI) throughout the entire attack process and has been working to enhance its actual attack capabilities.
According to the Genian Security Center (GSC), Kimsuky has advanced beyond previous methods of merely using AI for phishing images, audio, or decoy document generation. It has built its own local large language model (LLM) and retrieval-augmented generation (RAG) environments. There is also evidence of an AI-based development environment being operated.
North Korean hacking groups have previously targeted experts in diplomatic and security fields mainly by sending spear-phishing emails impersonating real business contacts. These emails would include ZIP compressed files containing malicious LNK (shortcut) files disguised as normal documents. When executed by the user, a PowerShell script would be activated in the background.
The circumstances identified in this analysis are notable because they indicate a more advanced attack methodology. Genian concluded that Kimsuky has set up a local LLM environment that does not transmit data to external services, which was then used to analyze stolen documents, extract necessary information, and partially automate the attack processes.
Specifically, traces were found demonstrating the use or establishment of local LLM execution and management tools such as Ollama, GPT4All, and Msty, as well as building or utilizing RAG environments, AI agent development frameworks, and speech recognition (STT) tools.
Numerous records were also discovered showing the installation and use of Cursor, an AI-based coding tool. There were signs that documents used in attacks were edited with Cursor and the results generated by AI were reviewed. Based on these findings, Genian determined that Kimsuky is conducting technology validation and research to use AI for developing malware and automating attacks.
The quality of decoy documents used for phishing attacks has also increased. While previously many cases involved reusing stolen legitimate documents, recently, documents related to virtual assets and finance, suspected to have been created by generative AI, have been used for attacks. The sentences and formats are now so realistic that they closely resemble actual business materials, thereby earning the recipient’s trust and luring them into executing malicious files.
In particular, virtual asset-related fields were identified as primary attack targets. Malicious documents disguised as investment strategy reports or financial materials continue to be distributed, and there was also evidence of efforts to check whether personal information—such as virtual asset wallet details, Gmail account credentials, and web service sign-up histories—had been exposed.
Genian explained that this case shows how nation-state-backed hacking organizations are expanding the use of AI from the attack preparation stage to actual execution, information processing, and automation domains.
Jonghyun Moon, Executive Director of the Genian Security Center, said, “This analysis indicates that nation-state-backed hacking groups are enhancing their attack capabilities by establishing local LLMs and AI development environments to incorporate AI into their actual attack frameworks. As AI technology advances and social engineering attacks become more sophisticated, it is increasingly important to utilize EDR-based threat hunting systems that focus on monitoring actual execution behaviors rather than just document content.”
The GSC tracks domestic and foreign cyber threats based on accumulated experience in threat analysis and intelligence within the national cybersecurity domain. Through monthly threat intelligence reports, they analyze threat trends, attack techniques, and major developments identified at actual cyberattack and breach sites.
Genian stated that the research outcomes from GSC not only contribute to strengthening national cybersecurity capabilities, but are also used as reference materials by major domestic and international threat analysis agencies and media outlets. The findings from this recent analysis of Kimsuky are being shared through cooperation networks including the Korea Internet & Security Agency’s (KISA) Threat Intelligence Network.
Hot Picks Today
"Can't Stand This: Why Change the Promised Bonus?"... 3,500 SK hynix Employees Rally
- Why Was the Taxi Driver Acquitted After Driving Following Three Shots of Soju During the Day?
- [Weather] Heat Eases but Daytime Heatwave and Nighttime Tropical Nights Persist
- "Eerie... Has She Predicted Even This?" Two of Baba Vanga's '2026 Prophecies' Already Coming True
- "Hannam The Wheel Youth Apartment Listed at 20 Million Won"... 'Bus House' Proposal Sparks Outrage Among Millennials and Gen Z
This analysis is drawing attention from the cybersecurity industry as it shows that North Korean hacking organizations have begun using generative AI not just as a phishing tool, but as a core means for information analysis, malware development, and attack automation.
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.