Crypto news

10.08.2026
19:31

Kimsuky embeds local AI models in attacks on the crypto industry

Lazarus Group КНДР хакеры

The North Korean hacker group Kimsuky, known for its targeted operations against the financial sector, has moved to a new level of technological evolution. South Korean cybersecurity experts have identified deployed local environments of large language models (LLMs) within the group's infrastructure, running on platforms such as Ollama, GPT4All, and Msty.

The key feature of these tools is full autonomy. They operate offline, using the Retrieval-Augmented Generation (RAG) method, which allows hackers to process requests without transmitting data to cloud services. This significantly reduces the risk of detection and traffic interception, making attacks more covert and resilient to analysis.

In addition to LLM environments, Kimsuky's arsenal includes libraries and frameworks for integrating language models into their own software, as well as the AI programming assistant Cursor and speech recognition tools. This set indicates a systematic approach: the group is not just experimenting with AI but actively embedding it into the full cycle of attack operations—from developing malicious code to data analysis and process automation.

A Pragmatic Approach to AI

Notably, Kimsuky is betting on ready-made open-source technologies rather than training its own models. This points to pragmatism and a drive for rapid adaptation. Using open LLMs allows the group to save resources and time, focusing on the ultimate goal—maximum attack effectiveness.

Special attention deserves the use of generative AI to create phishing materials. Generated documents imitating analytics on digital assets, investment strategies, and fintech services exhibit a high degree of realism. Some even replicate the design of a South Korean AI investment platform, making them nearly indistinguishable from legitimate ones.

This trend raises serious concern. The use of AI to generate convincing phishing dramatically elevates the threat level for crypto companies and individual investors. Combined with the recent Bybit lawsuit against North Korea and the Lazarus Group, the situation demonstrates that North Korean cybercriminals continue to expand their capabilities, and the industry urgently needs to adapt its defense mechanisms.

My analysis: Kimsuky's shift to local LLMs is an alarming signal for the entire sector. Traditional detection methods based on network traffic analysis are becoming less effective. Crypto companies should prioritize behavioral analysis and screening of incoming documents for AI generation, as well as consider AI as a potential weapon rather than just a defense tool.