North Korea’s hacking group Kimsuky has developed sophisticated AI-powered tools to automate cyberattacks, analyze stolen information, and produce more convincing phishing documents, according to a report from South Korean cybersecurity firm Genians published today [1, 2, 3, 4, 5].
Genians uncovered that Kimsuky operates local AI models including Ollama, GPT4All, and Msty—open source tools running offline to avoid detection. The group also uses retrieval augmented generation (RAG), a technique that enables them to search and analyze documents securely without sending data to external AI services [1, 2, 3, 4, 5].
Researchers found AI frameworks for agent development, speech-to-text software, and AI-assisted coding tools like Cursor integrated into Kimsuky-linked infrastructure, showing the group’s effort to embed AI into malware creation, data analysis, and attack automation [1, 2, 3, 5].
Kimsuky’s use of AI extends beyond phishing lures. The group is advancing the integration of generative AI into its cyber arsenal to increase the scale and sophistication of social engineering attacks. They deploy AI-generated decoy documents shaped as finance and cryptocurrency investment reports to trick targets into opening malicious files [1, 3, 5].
Since 2026, Kimsuky has used these AI-crafted spear-phishing documents to target military, diplomatic, and academic sectors, underlining a new phase in its espionage campaigns [4]. Genians said, "AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors. This change ... demonstrates that AI can enable the automation and large-scale production of social engineering attacks" [4].
North Korea’s state-linked cyber units, including Kimsuky, have been conducting global espionage, financial theft, and revenue generation operations for years. The US Treasury sanctioned Kimsuky in 2023 as a government-controlled cyber-espionage entity supporting Pyongyang’s strategic goals [1, 2, 3, 5].
Financially, North Korean hackers stole over $2 billion in cryptocurrency during the first nine months of 2025, illustrating their growing effectiveness in cybercrime [4]. Jenny Town, a senior fellow at the Stimson Center, noted, "North Korea’s hackers and programmers are more than capable of utilising and exploiting various AI tools to enhance their efforts. This is a new reality of all threat actors; North Korea is no exception" [4].
Genians’ report today provides detailed insight into Kimsuky’s expanding use of AI tools as of August 10, 2026 [1, 2, 3, 4, 5]. Future monitoring will focus on how Kimsuky further integrates AI into malware and attack automation techniques.