Internet

North Korean Hacker Kim Sukki Launches AI-Powered Attack… Analysis by GENIANS, INC.

Moving Beyond Simply Creating Phishing Lures to Directly Building Local AI Environments Attempts to Extract Confidential Information and Automate Attacks Virtual Assets and Finance Sectors Are Key Targets Sophisticated Spear-Phishing Attacks Utilizing AI to Mimic Real Business Documents

An Yu-ri
2026-08-10 08:29:56
[Edaily Reporter An Yu-ri ] "Kimsuky," a hacking group known to be affiliated with North Korea’s Reconnaissance General Bureau, is utilizing generative AI across its cyberattacks and accumulating related technical capabilities.

Flowchart of AI-Enabled Attacks (Photo: GENIANS, INC. Threat Intelligence Report)

GENIANS, INC.(263860), a cybersecurity firm, announced that its analysis of the latest attack activities by the North Korean hacking group “Kimsuky” revealed evidence that the group has been conducting research to integrate generative AI-based tools into its overall attack framework and has been accumulating related technical capabilities.

Until now, North Korean hacking groups have primarily targeted foreign affairs and national security experts by sending spear-phishing emails that impersonate actual professionals in those fields. A typical method involves the recipient executing a document-like malicious LNK (shortcut) file contained within a ZIP archive attached to the email, which then triggers a PowerShell script to run in the background.

Previously identified uses of AI by North Korean hacking groups were mainly concentrated in the attack preparation phase, such as image and voice forgery and the creation of phishing lures. However, this analysis revealed evidence that the threat actors went beyond simply using AI to create lures; they directly built local large language model (LLM) execution environments and search-augmented generation (RAG) environments, and operated AI-based development environments.

This is interpreted as an attempt to analyze compromised documents or automate information extraction and attack operations using local LLMs that can be operated without transmitting data to external services. Given that cyber threats, such as AI-enabled attacks, are becoming increasingly sophisticated and intelligent to the point of threatening national security and corporate survival, extreme caution is required.

Specifically, evidence was found that they had set up or utilized tools for running and managing local LLMs—such as Ollama, GPT4All, and Msty—as well as RAG configuration environments, Agent AI development frameworks, and speech-to-text (STT) tools.

In addition, numerous traces of the installation and use of Cursor—an AI tool specialized for coding—were identified, and records were found that appear to show documents used in attacks being edited with Cursor and the generated output being reviewed. GENIANS, INC. explained that this is a significant case suggesting that research and technical validation are underway to utilize AI for malware development and attack automation.

Attack techniques have also become significantly more sophisticated. While there were previously many cases of reusing stolen legitimate documents, recent attacks have been using documents related to virtual assets and the financial sector—believed to have been created using generative AI—as spear-phishing lures. This method aims to gain users’ trust through natural writing styles and a high level of polish comparable to actual business documents, thereby inducing them to execute malicious files.

In particular, this attack is noteworthy for targeting the virtual asset sector as a primary focus. Malicious documents disguised as investment strategy reports and financial materials were continuously distributed. During the analysis, evidence was also identified suggesting attempts to verify whether personal information—such as virtual asset wallet details, Gmail account information, and website registration history—had been exposed.

Moon Jong-hyun, Director of the GENIANS, INC. Security Center, emphasized, “This analysis demonstrates that state-sponsored hacking groups are enhancing their attack capabilities by establishing local LLM and AI development environments to integrate AI into their actual attack frameworks.” He added, “As social engineering attacks are expected to become even more sophisticated with the advancement of AI technology, an EDR-based threat hunting system that focuses on execution behavior rather than document content is of utmost importance.”

The findings of this analysis were included in the monthly threat intelligence report published by the GENIANS, INC. Security Center. These findings are being closely shared with domestic and international partner networks, including the Korea Internet & Security Agency (KISA) Threat Intelligence Network Consortium, and the full report is available on the GENIANS, INC. website.

Economy

Corporation

IT·Science

Economy

LX Semicon Begins Mass Production of Automotive Semiconductor MCUs… to Supply HyundaiMotor and KIA CORPORATION

LX Semicon has begun mass production of its automotive semiconductor, the “Motor-Specific MCU (Microcontroller Unit),” and will supply it to HyundaiMotor and KIA CORPORATION. This marks the first achi…
2026-08-10 08:55:43

Corporation

"Strengthening Global Supply Chain Competitiveness": Shinwon Accelerates AX

Shinwon ( Shinwon(009270)) announced on the 10th that it has established a dedicated artificial intelligence (AI) organization to drive data-driven AI Transformation (AX) innovation. With recent incre…
2026-08-10 08:54:14

IT·Science

NVIDIA Dominates the Sovereign AI Infrastructure Market as Well… Leading with a 92.4% Market Share

While countries around the world are accelerating efforts to build “sovereign AI” to ensure data sovereignty and technological independence, it has been revealed that they remain absolutely dependent …
2026-08-10 09:03:06