Kimsuky Deploys Local AI Stack to Automate Cyberattacks
Kimsuky, a state-sponsored hacking group linked to North Korea, has long targeted South Korean government, defense, diplomatic and financial organizations, as well as cryptocurrency businesses. Integrating generative AI into its operations could help the group analyze stolen material, write or modify malicious code and produce more convincing spear-phishing content, raising the speed and scale of campaigns without necessarily requiring greater staffing or technical expertise.
South Korean cybersecurity firm Genians said in an August 2026 report that Kimsuky had deployed local AI tools including Ollama, GPT4All and Msty, alongside retrieval-augmented generation, or RAG, systems. Researchers also found AI-agent development frameworks, speech-to-text software and the Cursor coding assistant. The stack could support malware development, document analysis and attack automation, while generating finance- and cryptocurrency-themed lures. The findings, reported on Aug. 10, had not been independently verified.
All Coverage
3 original reportsThe Backstory
The history behind this eventMicrosoft Says North Korean Hackers Are Using AI Agents to Automate Cyberattacks and IT Fraud
North Korea has long placed remote IT workers using false identities inside U.S. and European companies, generating foreign currency for Pyongyang and potentially gaining access to sensitive systems. U.S. Justice Department data show that more than 300 U.S. companies were infiltrated from 2020 to 2024, with at least $6.8 million flowing to the North Korean government. The figures underscore how recruitment processes have become a corporate cybersecurity vulnerability.
Microsoft Threat Intelligence said on March 6, 2026, that Coral Sleet and Jasper Sleet had used AI agents to automate reconnaissance, attack infrastructure, and command-and-control operations. They also used Face Swap, voice-changing software and generative AI to fabricate identities. Microsoft disrupted 3,000 related Outlook and Hotmail accounts in 2025, while the latest reports on March 15 said the fraud was expanding from the United States into Europe.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.