- North Korea’s Kimsuky hacking group is now running AI models offline on its own servers, moving beyond public chatbots to build AI into its attack workflow.
- South Korean security firm Genians discovered the group using tools like Ollama, GPT4All, and Msty to connect documents to AI systems, including a request to check datasets for wallet details and credentials.
- The group has also assembled developer libraries for custom AI functions and speech-to-text tools, signaling a shift toward automated, harder-to-detect cyber espionage operations.
North Korean state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups, Kimsuky, has begun running artificial intelligence offline on its own servers, connecting document-search tools to files in its possession and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the setup after months of tracking and log analysis on infrastructure tied to the hacking unit under North Korea’s Reconnaissance General Bureau.
Genians found no evidence that the group had trained an AI model of its own. The firm describes an actor in a “research and knowledge acquisition” stage, assembling and testing existing tools rather than making new models, with the apparent aim of folding AI through the operation, from writing malware to analyzing data. For an intelligence unit that has spent years phishing government, research, and other strategic targets, that points to attacks that are quicker to prepare and harder to spot.
The core evidence is tools for running language models offline: Ollama, GPT4All and Msty, all found on infrastructure Genians linked to the group. The report says they were run or configured, not merely downloaded. Genians’ report tells defenders to correlate LNK execution, PowerShell, hidden scheduled tasks, GitHub traffic, and later payload activity instead of judging a lure mainly by how polished it looks.
The researchers separately recovered an operator request to check a data set for wallet details, Gmail credentials and site-registration history, ending, “The more detailed the analysis, the better. Please do not do it haphazardly.” The report could not confirm that this particular request was submitted to an AI service. The group did not stop at ready-made apps, also finding developer libraries including LLaMaSharp, Microsoft’s Semantic Kernel and Microsoft.Agents.AI, components for building AI functions into custom C# and .NET software.
Fortinet separately documented the broader GitHub-C2 pattern in April in attacks targeting South Korean users. The newly observed offline stack has not been shown running against a victim in the reporting to date, and no victim count has been disclosed. The U.S. Treasury, which sanctioned Kimsuky in 2023, describes it as subordinate to the Reconnaissance General Bureau and primarily focused on intelligence collection. The step also fits a pattern Genians flagged in 2025, when it linked Kimsuky to a spear-phishing attack that used ChatGPT-generated images of South Korean military employee ID cards.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
