North Korean state-linked hacking group Kimsuky is utilizing artificial intelligence to automate and scale sophisticated spear-phishing attacks targeting military, diplomatic, and academic sectors, according to a new report.
Key Points
- South Korean cybersecurity firm Genians identified Kimsuky’s use of AI to generate malicious documents disguised as legitimate research reports and invitations.
- The hackers utilize offline, open-source tools including Ollama, GPT-4All, and Msty to run large language models without triggering internet-based security detections.
- This shift allows threat actors to produce high-quality, deceptive content rapidly, significantly increasing the efficiency of large-scale social engineering campaigns.
- North Korean state-backed groups have a history of cyber operations, including the theft of over $2 billion in cryptocurrency during the first nine months of 2025.