Internet

North Korean Hacker Kim Sukki Launches AI-Powered Attack… Analysis by GENIANS, INC.

Moving Beyond Simply Creating Phishing Lures to Directly Building Local AI Environments Attempts to Extract Confidential Information and Automate Attacks Virtual Assets and Finance Sectors Are Key Targets Sophisticated Spear-Phishing Attacks Utilizing AI to Mimic Real Business Documents

An Yu-ri
2026-08-10 08:29:56
[Edaily Reporter An Yu-ri ] "Kimsuky," a hacking group known to be affiliated with North Korea’s Reconnaissance General Bureau, is utilizing generative AI across its cyberattacks and accumulating related technical capabilities.

Flowchart of AI-Enabled Attacks (Photo: GENIANS, INC. Threat Intelligence Report)

GENIANS, INC.(263860), a cybersecurity firm, announced that its analysis of the latest attack activities by the North Korean hacking group “Kimsuky” revealed evidence that the group has been conducting research to integrate generative AI-based tools into its overall attack framework and has been accumulating related technical capabilities.

Until now, North Korean hacking groups have primarily targeted foreign affairs and national security experts by sending spear-phishing emails that impersonate actual professionals in those fields. A typical method involves the recipient executing a document-like malicious LNK (shortcut) file contained within a ZIP archive attached to the email, which then triggers a PowerShell script to run in the background.

Previously identified uses of AI by North Korean hacking groups were mainly concentrated in the attack preparation phase, such as image and voice forgery and the creation of phishing lures. However, this analysis revealed evidence that the threat actors went beyond simply using AI to create lures; they directly built local large language model (LLM) execution environments and search-augmented generation (RAG) environments, and operated AI-based development environments.

This is interpreted as an attempt to analyze compromised documents or automate information extraction and attack operations using local LLMs that can be operated without transmitting data to external services. Given that cyber threats, such as AI-enabled attacks, are becoming increasingly sophisticated and intelligent to the point of threatening national security and corporate survival, extreme caution is required.

Specifically, evidence was found that they had set up or utilized tools for running and managing local LLMs—such as Ollama, GPT4All, and Msty—as well as RAG configuration environments, Agent AI development frameworks, and speech-to-text (STT) tools.

In addition, numerous traces of the installation and use of Cursor—an AI tool specialized for coding—were identified, and records were found that appear to show documents used in attacks being edited with Cursor and the generated output being reviewed. GENIANS, INC. explained that this is a significant case suggesting that research and technical validation are underway to utilize AI for malware development and attack automation.

Attack techniques have also become significantly more sophisticated. While there were previously many cases of reusing stolen legitimate documents, recent attacks have been using documents related to virtual assets and the financial sector—believed to have been created using generative AI—as spear-phishing lures. This method aims to gain users’ trust through natural writing styles and a high level of polish comparable to actual business documents, thereby inducing them to execute malicious files.

In particular, this attack is noteworthy for targeting the virtual asset sector as a primary focus. Malicious documents disguised as investment strategy reports and financial materials were continuously distributed. During the analysis, evidence was also identified suggesting attempts to verify whether personal information—such as virtual asset wallet details, Gmail account information, and website registration history—had been exposed.

Moon Jong-hyun, Director of the GENIANS, INC. Security Center, emphasized, “This analysis demonstrates that state-sponsored hacking groups are enhancing their attack capabilities by establishing local LLM and AI development environments to integrate AI into their actual attack frameworks.” He added, “As social engineering attacks are expected to become even more sophisticated with the advancement of AI technology, an EDR-based threat hunting system that focuses on execution behavior rather than document content is of utmost importance.”

The findings of this analysis were included in the monthly threat intelligence report published by the GENIANS, INC. Security Center. These findings are being closely shared with domestic and international partner networks, including the Korea Internet & Security Agency (KISA) Threat Intelligence Network Consortium, and the full report is available on the GENIANS, INC. website.

Economy

Corporation

IT·Science

Economy

[Interview] “100°C Steam on a Mop Instead of the Floor”… LG Corp. RoCheong Bets Big on ‘Mop Steam’

"Instead of spraying 100°C steam directly onto the floor, we opted to spray the steam directly onto the mop to heat the mop itself. This is to minimize damage to hardwood and vinyl floors and to bette…
2026-09-17 04:00:04

Corporation

Shinsegae Co.,Ltd to Hold Open Recruitment for New Employees… Application Submission Begins on the 18th

Shinsegae Co.,Ltd announced on the 17th that it will conduct an open recruitment drive for new employees in 2027. Ten affiliates are participating in the open recruitment: E-MART Co., Ltd.(139480), #S…
2026-09-17 06:00:06

IT·Science

"Overtime Is a Given, but Company Dinners Are Optional"... SKT Assigns "Employee Numbers" to AI Employees and Welcomes Them as Colleagues

At 2 a.m., a digital ad campaign went live. While a human would have already clocked out and gone to sleep by this hour, the AI agent reviews the ad’s performance without showing any signs of fatigue.…
2026-09-17 04:05:04