North Korean spies are running local LLMs to cause AI mischief

← Back to the feed

North Korean spies are running local LLMs to cause AI mischief

The Register · 5 hours ago

North Korean state-sponsored hacking group Kimsuky is developing local, offline AI capabilities to strengthen its cyber-espionage operations, according to South Korean security firm Genians. The researchers found the group operating local large language model environments using tools such as Ollama, GPT4All and Msty, alongside retrieval-augmented generation for document searches, allowing it to use AI without sending data to cloud services where it might be detected or blocked. Genians said this marks a shift from one-off experimentation to sustained preparation for embedding AI into real attack capabilities, including malware development and data analysis.

Kimsuky, which operates under North Korea's Reconnaissance General Bureau, has long used phishing emails with malicious ZIP and LNK files disguised as documents related to international events or business, which trigger PowerShell loaders to harvest system information when opened. Investigators found the group is now using AI to craft more convincing, natural-language phishing lures, particularly around virtual assets and finance, while continuing to rely on public GitHub repositories for command-and-control infrastructure. These repositories also revealed the group collecting AI development libraries such as LLaMaSharp and Microsoft.Extensions.AI, and packages for integrating commercial AI services, spanning local execution, document retrieval, automated agents and external AI integration.

  • Kimsuky hackers run local LLMs to avoid cloud detection
  • AI now used to craft more convincing phishing lures
  • Group collects AI libraries for malware and automation development

AI Asia Cybersecurity Technology World

Read the full article at the source →