North Korean hackers build AI tools to automate cyberattacks, report says

North Korean hacking group Kimsuky built local AI tools including Ollama, GPT4All and Msty to automate attacks and generate convincing phishing campaigns without sending data to outside services.

Categorized in: AI News IT and Development
Published on: Aug 10, 2026
North Korean hackers build AI tools to automate cyberattacks, report says

South Korean cybersecurity firm Genians has found evidence that the North Korean hacking group Kimsuky built tools to run artificial intelligence models locally, a shift that could allow the group to automate cyberattacks and produce more convincing phishing campaigns without sending sensitive data to outside AI services.

The group set up local AI management tools including Ollama, GPT4All and Msty, alongside retrieval augmented generation (RAG) document search technology. Genians also found AI agent development frameworks, speech-to-text software, and Cursor, an AI-assisted coding tool, on infrastructure linked to the campaign.

Genians said the setup allows operators to process documents locally, avoiding data leaks to external services. The findings indicate Kimsuky is building capacity to integrate existing AI models into malware development, data analysis, and attack automation.

AI-generated decoys for financial intelligence

Genians also found finance and cryptocurrency-themed decoy documents that appeared to have been generated with AI. The materials were about portfolios and other workplace documents, designed to appear legitimate enough to trick targets into opening them.

The company's findings could not be independently verified.

"The tools could allow operators to process documents without sending sensitive information to outside AI services," Genians said in the report.

The group's expansion into AI-based tooling follows years of known North Korean cyber activity. The U.S. Treasury sanctioned Kimsuky in 2023 as a state-controlled cyber-espionage group gathering intelligence in support of Pyongyang's strategic objectives.

How Kimsuky built local AI infrastructure

The infrastructure setup included open-source LLM frameworks, local AI runtimes, and document search systems commonly used by developers. Genians said the kits were configured to run without sending data to cloud API services like ChatGPT.

By hosting AI models locally, Kimsuky avoids sending sensitive stolen documents to external servers - a move that also bypasses detection by security systems monitoring outbound API calls.

Why this matters for IT and development professionals

The practical effect for developers is that AI-assisted tooling once limited to license-screened environments is now being repurposed by state-backed actors for real campaign operations. AI Learning Path for Cybersecurity Analysts covers detection, threat modeling, and security automation - skills that contrast with the offensive capabilities now confirmed.

Organizations that deploy AI coding aids or local model agents should prepare for adversaries to use similar stacks to generate polymorphic malware or automate social engineering at scale.


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)