North Korea's hacking group Kimsuky is expanding its use of generative artificial intelligence (AI) from simple phishing material creation to the analysis of stolen information and automation of attacks. Evidence has emerged that they have established a local large language model (LLM) environment that does not rely on external services.
On August 10, cybersecurity firm Genians released an analysis of Kimsuky's latest attack activities, revealing the use of local LLM execution and management tools such as Ollama, GPT4All, and Msty. Traces of AI agent development frameworks and voice recognition tools have also been detected, including a search-augmented generation (RAG) environment.
Records indicate the use of Cursor, an AI-based code editor, suggesting that it may have been employed to edit documents for attacks and review AI-generated outputs.
Previously, Kimsuky's use of AI was primarily limited to preparing attacks, such as creating fake images, audio, or phishing messages. However, this time, they have independently built a local LLM and RAG environment, indicating a shift towards automating the analysis of stolen documents and extracting necessary information for repetitive attack tasks.
Unlike past tactics where Kimsuky focused on impersonating experts or officials to deliver malicious documents and links, the newly detected local LLM and RAG environment appears aimed at automating information analysis and attack preparation, thereby increasing the speed and scale of their operations.
The bait used in these attacks has also become more sophisticated. Previously, they often recycled stolen legitimate documents, but recent findings confirm the use of investment reports and financial materials likely generated by AI for spear phishing.
These documents are crafted to resemble natural language and actual work materials, lowering user suspicion and leading them to execute attached malicious files, thereby stealing account or personal information.
The cryptocurrency sector has emerged as a primary target. Analysts believe attackers are attempting to access personal financial and online activity information, including cryptocurrency wallet details and Gmail accounts.
Moon Jong-hyun, head of the Genians Security Center, stated, “State-backed hacking groups are enhancing their attack capabilities by integrating AI into their operational frameworks, including the establishment of local LLM and AI development environments. It is crucial to have an endpoint detection and response (EDR) based threat hunting system that focuses on execution actions rather than document content.”
Meanwhile, Genians Security Center is sharing these analysis results with domestic and international partner organizations, including the Korea Internet & Security Agency (KISA) threat intelligence network.
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
