SEOUL, August 10 (AJP) - North Korean hacking group Kimsuky has apparently built its own local large language model environment as it expands its use of artificial intelligence from creating phishing lures to extracting information and automating cyberattacks, a South Korean cybersecurity firm said Monday.
Genians said its analysis found signs that the group had deployed local AI tools including Ollama, GPT4All and Msty, as well as retrieval-augmented generation, or RAG, technology. Such systems could allow hackers to analyze stolen documents and automate parts of cyber operations without sending sensitive data to external AI services.
The group was also found to be using what appeared to be AI-generated financial and cryptocurrency documents as spear-phishing lures. The malicious files were designed to resemble legitimate business documents and potentially expose cryptocurrency wallet information, Gmail account data and other personal information, according to Genians.
Kimsuky is a North Korean cyberespionage group subordinate to the Reconnaissance General Bureau, the country's main foreign intelligence agency. Active since at least 2012, it has mainly used spear-phishing campaigns to target government officials, researchers, think tanks, academics and journalists in South Korea and other countries.
The U.S. Treasury sanctioned Kimsuky in November 2023, saying its intelligence-gathering operations support North Korea's strategic and nuclear ambitions.
Copyright ⓒ Aju Press All rights reserved.



