North Korea-linked Kimsuky used local AI for crypto phishing

Researchers say Kimsuky tested local large language models and used AI-generated phishing since early 2026 to target virtual assets.

Genians Security Center reported that months of monitoring infrastructure tied to the North Korea-linked group Kimsuky found installations of local large language models and other AI tools. The activity began in early 2026 and included generative AI-created documents used in spear phishing aimed at virtual asset holders and related professionals.

The investigators identified local platforms Ollama, GPT4All and Msty running on systems linked to the group. They also found AI development frameworks such as Microsoft Semantic Kernel, Microsoft Agents AI and LLaMaSharp, along with connectors for OpenAI and Azure OpenAI services. GPT4All’s LocalDocs feature had been configured; that feature lets an AI search a set of documents before answering questions, a technique known as retrieval-augmented generation.

The report detailed how generative AI was used to produce decoy documents for targeted emails. Phishing lures were often delivered as ZIP archives containing Windows shortcut (LNK) files that, when opened, executed hidden PowerShell commands while displaying a realistic PDF. The shortcuts allowed programs to run without immediately alerting the user.

Researchers found remote-access malware hidden in software repositories. AsyncRAT payloads were encrypted and disguised as image files with names such as “apple.png,” “fox.png” and “wolf.png.” Git repositories were observed serving as command-and-control infrastructure for those payloads.

Logs and artifacts contained indicators linked to North Korean operators. The system manufacturer field showed “Arirang,” a brand associated with North Korean devices. Korean-language files and linguistic patterns identified in the logs matched usage the analysts associated with North Korea. One log entry showed a Korean-language query about disabling Microsoft Defender’s reporting feature that had been translated into English and submitted to a cloud chatbot. Searches related to virtual assets, including queries about where bitcoin users could be found, were also present in the collected data.

The analysis found no evidence that Kimsuky had trained its own large models or assembled large training datasets. Instead, the group appears to be integrating existing local models, speech recognition tools and cloud connectors into its toolkit. The report noted the presence of retrieval-augmented generation, speech-to-text components and AI agent frameworks alongside the group’s established malware tools.

Genians assessed Kimsuky as operating under North Korea’s Reconnaissance General Bureau. The report describes the group’s use of AI tools and existing malware techniques and provides technical indicators tied to the observed infrastructure.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author