AI is increasingly becoming a tool for cybercriminals and state-backed hacking groups around the world. A new report suggests that North Korea hacking group Kimsuky is taking a step further with the use of AI. According to South Korean cybersecurity company Genians, Kimsuky is experimenting with a range of AI-related tools that can help it automate cyberattacks, analyse the information that has been stolen, develop malware and even create more successful phishing campaigns. The findings from this report indicate a shift from using generative AI to write phishing messages to going deeper into the cyberattack flow.Genians found evidence that Kimsuky had established local environments for running large language models (LLMs), including Ollama, GPT4All and Msty. It has even identified the use of retrieval-augmented generation (RAG), AI development frameworks, speech-to-text software and the AI-assisted coding platform Cursor. It is important to note that the findings have not been independently verified. But the report gives a clear idea of how AI is increasingly becoming a part of the cyberattack ecosystem. Here is everything you need to know about this finding:About The AuthorAarohy Kapoor is a dynamic content producer and editor, known for creating high-impact, consumer-first content across diverse categories including technology, home decor, health & fitness, food, pet care, sports and everyday lifestyle essentials. With a strong editorial experience and an understanding of modern consumer behaviour, she specialises in product reviews, comparison articles, buying guides and deal-led content that simplify decision-making for readers.
North Korean Hackers Are Building AI Tools For Cyberattacks: What We Know About Kimsuky’s New Strategy
North Korean hacking group Kimsuky is reportedly building AI capabilities to automate cyberattacks, analyse stolen data and create convincing phishing lures. Here is everything you need to know about these hackers and the new strategy of Kimsuky.
Kimsuky (North Korea) is deploying local LLMs and Cursor (AI coding) to automate cyberattacks, malware, and phishing—Genians report. Nation-state operationalization of AI signals security stacks must account for AI-powered attacks on detection and response.










