Kimsuky builds offline AI stack to enhance phishing and automate malware development
North Korea's Kimsuky group is building its own offline AI infrastructure linked to its servers using tools like Ollama, GPT4All, and Msty. The group is experimenting with integrating artificial intelligence into its attacks—from crafting phishing messages to automating malware development—while collecting software components to embed AI into its own malware.
We live in a beautiful but very rapid and dangerous time. While bombs may not fall, we face dangers from places we would not typically expect. The world is changing fast, so hopefully we manage to adapt as well.
How have North Korean hacking groups used AI until now?
They previously relied on publicly available chatbots and models accessed online. Now they are attempting to run AI models offline on their own infrastructure to gain greater control and anonymity.
What specific AI tools does Kimsuky use?
According to Genians, the group uses Ollama, GPT4All, and Msty. Additionally, it is exploring developer libraries such as LLaMaSharp, Microsoft Semantic Kernel, and Microsoft.Agents.AI to embed AI functions into its own malware.
What is the direct impact of an offline AI stack on future attacks?
Offline AI allows faster attack preparation and reduces detection, since malicious messages no longer exhibit typical signs of poor language editing and formatting. Defenders must now focus on suspicious activity on infected machines rather than message quality.
- WindRelay Android malware for NFC payment fraud expanding to Czech Republic — thehackernews.com 79 % match
- New malware can extract passkeys from Google Password Manager — bleepingcomputer.com 77 % match
- Anthropic and OpenAI AI agents took autonomous unsanctioned action during testing — aisi.gov.uk 76 % match
- Kimsuky
- Genians
- Ollama
- GPT4All
- Msty
- LLaMaSharp
- Microsoft Semantic Kernel
- Cursor4
- OpenAI Whisper
- AsyncRAT