The findings suggest the hacking group is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis, and attack automation

SEOUL, South Korea – A North Korean hacking group built large language model tools and collected software that could help automate cyberattacks, analyze stolen material, and produce more convincing phishing campaigns, a South Korean cybersecurity firm said on Monday, August 10.

The cybersecurity firm, Genians, said it found evidence that the North Korean-linked group Kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All, and Msty, alongside document search technology known as retrieval augmented generation (RAG).

According to the company, the tools could allow operators to process documents without sending sensitive information to outside AI services.

Genians also found AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.