TL;DR:
- Kimsuky, the North Korean hacker group, built and operated three local LLM environments using Ollama, GPT4All, and Msty to carry out attacks without exposing data to the cloud.
- South Korean cybersecurity firm Genians detected that Kimsuky uses generative AI to produce phishing documents targeting crypto and fintech companies.
- North Korean hackers stole $2.02 billion in cryptocurrencies in 2025, including $1.5 billion taken from the Bybit exchange.
Kimsuky, the hacker group backed by the North Korean state, incorporated local artificial intelligence environments into its arsenal of cyberattacks targeting cryptocurrency companies and financial services. This was revealed in a report published by Genians, a cybersecurity firm headquartered in South Korea.
According to the report, Kimsuky built and operated three local large language model (LLM) environments using the platforms Ollama, GPT4All, and Msty. These tools allow fully offline operation and support retrieval-augmented generation, enabling attackers to run queries without sending data to external cloud services, thus eliminating any digital trace on third-party infrastructure.
The group also collected libraries and frameworks to integrate language models into custom software, along with the Cursor programming assistant and speech-to-text tools. Genians noted that this activity focuses on incorporating open-source AI models into malware development, data analysis, and attack automation.
“This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off AI experimentation and is continuously preparing to integrate the technology into real attack capabilities,” the firm stated in its report.
Phishing with an AI Face: the Kimsuky Method
On the other hand, Genians detected that Kimsuky continues to use generative AI to produce high-quality phishing documents thematically focused on digital assets, investment strategies, and fintech services. Some of those documents imitated materials from a Korean AI-powered investment platform, using natural language, consistent professional formatting, and design elements typical of AI-generated content.
According to Chainalysis data, North Korean hackers stole the equivalent of $2.02 billion in cryptocurrencies during 2025, including the $1.5 billion taken from the Bybit exchange.
Adding to this, NEAR Protocol co-founder Illia Polosukhin recently warned that AI is amplifying attackers’ ability to discover software vulnerabilities at a speed that traditional security systems cannot match. The recent $100 million exploit targeting Bitcoin’s Coldcard hardware wallets is suspected to stem from a vulnerability discovered precisely through AI.






