Go Back

North Korea’s Kimsuky Turns Local AI Into Crypto Attack Tool

North Korea’s Kimsuky Turns Local AI Into Crypto Attack Tool

Murugaverl Mahasenan

Murugaverl Mahasenan

Make Catenaa preferred on (opens in a new tab)

Catenaa, Saturday, August 15, 2026-North Korea-linked hacking group Kimsuky is building locally operated artificial intelligence systems that could make attacks against cryptocurrency and financial organizations harder to detect and disrupt, according to new cybersecurity research.

South Korean cybersecurity firm Genians said Monday it found evidence that Kimsuky had built environments using Ollama, GPT4All and Msty, tools that allow large language models to run locally rather than through commercial cloud services.

That distinction could matter for defenders.

Running AI locally allows attackers to process stolen information, develop malicious software and automate parts of an operation without sending sensitive data to an outside AI provider. It also reduces the digital trail that commercial AI services could potentially detect or restrict.

Genians assessed that Kimsuky is not developing its own AI models. Instead, the group appears to be assembling existing open-source technology into a broader attack system.

Researchers also found AI coding tools, speech-to-text software and frameworks that can connect language models with custom applications.

The findings suggest AI is shifting from a tool for creating convincing phishing messages into part of the infrastructure supporting cyberattacks.

Crypto remains among the targets.

Genians identified AI-generated documents built around cryptocurrency, investment and fintech themes. The documents were designed to resemble professional financial materials, potentially making malicious files or links more convincing to employees.

The group continues to target the virtual asset sector alongside diplomatic, military and security organizations, Genians said.

The development carries added weight because North Korean cyber operations have already become one of the crypto industry’s largest security threats. North Korean hackers stole about $2.02 billion in cryptocurrency during 2025, according to Chainalysis data cited in industry reports.

The record included the roughly $1.5 billion Bybit attack.

Kimsuky’s approach differs from attacks that simply ask public AI services to write malicious code. Local models can be connected directly to stolen documents, malware-development environments and other attack tools.

That could eventually allow attackers to analyze large amounts of stolen information and identify valuable targets faster.

Genians said the evidence indicates Kimsuky is still building those capabilities rather than operating a fully autonomous AI attack system.

But the direction is clear: AI is becoming part of the attack chain itself, raising the possibility that crypto firms will increasingly face cyber campaigns that can research, customize and refine attacks at machine speed.