The North Korean-linked Kimsuky group has begun using AI tools to automate its cyberattacks and analyze information.
It has been revealed that the Kimsuky hacker group, linked to North Korea, is developing AI-based tools for use in cyberattacks. According to a report prepared by the South Korea-based cybersecurity company Genians, the group is using various software to run and manage AI models on local systems.
Genians’ investigations that revealed the infrastructure associated with Kimsuky includes major language modeling tools such as Ollama, GPT4All, and Msty. It was also determined that the attackers are actively using RAG (Retrieval Augmented Generation) technology, which allows them to perform more advanced searches on documents.
This technological structure allows sensitive documents to be processed on local systems without needing to be sent to external AI services for analysis. Thus, attackers gain the ability to analyze the data they obtain within their own systems without exporting it.
The Era of AI in Cyberattacks
Findings shared by Genians reveal that Kimsuky is not only using generative AI to create more convincing phishing messages. The group is preparing to incorporate broader AI models into much processes such as developing malicious software, analyzing stolen data, and automating cyberattacks.
Security experts have also identified that Kimsuky creates fraudulent documents related to finance and cryptocurrencies. These documents, believed to be created using AI, are designed to mimic legitimate investment reports and corporate business documents. The aim of such content is to gain the trust of individuals, thereby increasing the success rate of phishing and social engineering attacks.
Kimsuky and State-Backed Operations
Kimsuky has long been known as a group associated with cyber operations linked to North Korea. The North Korean regime actively uses state-affiliated hacker groups for espionage, financial theft, and revenue generation. The inclusion of AI tools in these operations indicates that the threat level in the cybersecurity world has reached a new dimension.
In your opinion, what should be the most critical measure that institutions take against these AI-based attacks?