South Korean Firm Genians Says North Korea-Linked Kimsuky Group Built Local AI Tools for Cyberattacks
The Facts
- Genians, a Seoul-based cybersecurity firm, said in a report released Monday that the North Korea-linked group Kimsuky built large language model tools and collected software that could help automate cyberattacks, analyse stolen material and produce more convincing phishing campaigns.
- Genians said it found evidence Kimsuky had set up tools for running and managing AI models locally — including Ollama, GPT4All and Msty — alongside document search technology known as retrieval-augmented generation (RAG).
- Running the models locally and offline would allow operators to process documents without sending sensitive information to outside AI services, keeping activity away from commercial providers that log usage and screen for abuse.
- Genians also reported finding AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.
- The firm said the findings indicate Kimsuky is moving beyond using generative AI to create phishing lures and toward integrating existing AI models into malware development, data analysis and attack automation.
- Targets described in the reporting include military, diplomatic and academic institutions, as well as cryptocurrency and financial firms.
- Genians said the group used AI to generate decoy documents disguised as legitimate material such as research reports, invitations and finance- or cryptocurrency-themed files, used in spear-phishing attacks.
- The report documents AI software and frameworks found on infrastructure attributed to the group and describes what those tools could enable; coverage frames the automation as emerging capacity rather than demonstrated fully automated attacks.
Context
What is retrieval-augmented generation (RAG), and why does it matter here?
RAG is a document search technology that lets a language model pull in and reference stored documents when answering queries Reuters. Genians said Kimsuky's local setups support RAG, enabling queries against collected material without sending data to external cloud services Block, which would let operators sift large volumes of stolen documents in-house DT News.
Why would a hacking group run its own AI models instead of using commercial chatbots?
Open tools such as Ollama, GPT4All and Msty can run large language models without an internet connection Al Jazeera Online. Researchers say that keeps sensitive work away from commercial providers, which log activity and screen for abuse, and avoids the guardrails and monitoring built into public AI services Next Web,AMBCrypto.
Who is Kimsuky, and what is the broader context around North Korea-linked cyber operations?
Kimsuky is a cyber-espionage group tied to North Korea's intelligence services that targets governments, researchers and businesses Al Jazeera Online,AMBCrypto. Separately, blockchain intelligence firm TRM Labs reported that North Korea-linked groups accounted for roughly $643 million in stolen cryptocurrency in the first half of 2026 — about 66% of global crypto hacking losses out of $972 million across 207 incidents — and more than $2.06 billion in digital assets in 2025 Cryptopolitan.
Where Left and Right agree, and where they split
- Where Left and Right agree
- Kimsuky's local, offline AI stack is treated by both as real emerging capability aimed at military, diplomatic, academic and financial targets — not hypothetical risk.
- Where Left and Right split
- Whether the story is about AI safety collapsing the moment models run off-vendor, or about an adversary state gaining automated attack capacity that targets must be hardened against.
How left and right read it
The whole architecture of AI safety we have been sold rests on providers logging usage and screening for abuse — and running Ollama, GPT4All and Msty locally routes around that entirely, letting operators process stolen documents offline with retrieval-augmented search. Voluntary guardrails end at the vendor's edge. When the targets are academic, diplomatic and military institutions, safety built on a provider's goodwill is not safety at all.
An adversary state that can automate intrusions is a national security problem before it is a technology one. Kimsuky moving beyond phishing lures toward malware development, data analysis and attack automation — with agent frameworks and an AI coding tool on its infrastructure — is capability pointed at military, diplomatic and academic institutions and at financial and cryptocurrency firms. Harden them now. Warning from a Seoul-based firm deserves that seriousness.
The receipts — all 31 sources
Wire services (2)
Independent coverage (29)
Facts first. Then every angle.
The day’s biggest stories in one short brief — the facts everyone agrees on, then the competing values behind the headlines. Free in your inbox.