North Korea’s hackers have found a way to harness AI without ever handing their secrets to a Silicon Valley company. According to the South Korean cybersecurity firm Genians, the state-linked group Kimsuky has been building its own AI tools to automate and sharpen its cyberattacks.

The clever part is how deliberately it stays off the grid. Rather than lean on commercial chatbots, which log activity and screen for abuse, the group is running open models such as Ollama, GPT4All and Msty directly on its own machines, which keeps sensitive work away from any provider that might notice or report it.

That choice is the whole strategy in miniature. By keeping everything local, Kimsuky sidesteps the monitoring and safety filters that firms like OpenAI have built precisely to catch this kind of misuse, turning freely available AI software into an in-house weapon nobody else can see running.

The toolkit goes well beyond a chatbot, too. Genians says the group has pulled in retrieval-augmented generation to sift stolen documents, AI agent frameworks to string tasks together, speech-to-text software, and even Cursor, the AI-assisted coding tool, to help write and refine its malware.

With that stack in hand, the group can work faster and more convincingly across the board. The researchers describe it automating attacks, crafting more believable phishing lures, weaving AI into malware development, and analysing whatever it steals, all without the bottleneck of doing each step by hand.