A South Korean cybersecurity firm has uncovered evidence suggesting that North Korea's hacking group Kimsuky is developing tools based on artificial intelligence (AI) to automate cyberattacks. According to Genians, a Seoul-based cybersecurity company, the group has created software capable of analyzing stolen data, generating convincing phishing campaigns, and automating attacks using large language models. The findings were revealed on August 10, 2026, following analysis of digital artifacts linked to the group’s activities. The tools developed by Kimsuky reportedly include a local language model and environment designed for deploying generative AI throughout the attack process. This system works alongside a document search technology known as Retrieval-Augmented Generation (RAG). These capabilities allow operators to process documents without transmitting sensitive information to external AI services, reducing exposure risks. Additionally, Genians identified software for converting speech into text and encoding tools powered by AI, according to Spanish news agency EFE. The firm noted that Kimsuky is not merely using generative AI for crafting phishing emails but is expanding its integration into the broader development of malicious software, data analysis, and automated attacks. Among the discovered materials were fabricated financial documents and cryptocurrency-related files clearly generated with AI assistance. These documents were crafted to resemble legitimate investment reports and other business-related paperwork, making them more likely to deceive targets. North Korea has long been associated with cyber units tied to state interests, engaging in espionage, financial theft, and revenue generation through cyber operations. U.S. and South Korean authorities, along with cybersecurity experts, have highlighted this pattern over the years. In 2023, the U.S. Department of Treasury imposed sanctions against Kimsuky, designating it as a cyber-espionage group under the control of the North Korean government, which gathers intelligence to achieve strategic objectives in Pyongyang. Kimsuky has previously been linked to several high-profile cyber incidents targeting governments, corporations, and international organizations. Its activities often involve infiltrating networks, stealing confidential information, and disrupting critical infrastructure. The group has shown a particular interest in financial institutions, aiming to exploit vulnerabilities in banking systems and cryptocurrency platforms. The use of AI represents a significant evolution in their tactics, allowing for greater efficiency and sophistication in executing cyberattacks. Experts suggest that the incorporation of AI technologies could make future cyber threats from North Korea even more challenging to detect and mitigate. Traditional methods of identifying malicious activity rely heavily on signature recognition and behavioral analysis, both of which can be circumvented by AI-generated content that mimics legitimate user behavior. This advancement underscores the need for updated defensive strategies and increased collaboration among global cybersecurity agencies. The discovery comes amid growing concerns about the proliferation of AI-driven cyber threats worldwide. Governments and private sector entities are increasingly investing in AI-based security solutions to counter these emerging risks. However, the dual-use nature of AI, where the same technologies can be employed for both defensive and offensive purposes, raises complex ethical and regulatory questions. As AI becomes more accessible, distinguishing between benign and malicious uses will become an ongoing challenge for cybersecurity professionals. In response to the revelations, South Korean officials have reiterated their commitment to strengthening national defenses against cyber threats. They have also called for enhanced international cooperation to address the evolving landscape of cyber warfare. Meanwhile, cybersecurity firms continue to monitor developments related to Kimsuky and other North Korean hacking groups, seeking to stay ahead of potential threats posed by advanced AI integration.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.
Become a Supporter