North Korean Hackers Develop AI Tools to Automate Cyberattacks: Report

North Korean-linked group Kimsuky is using AI tools to analyse stolen data, develop malware and automate cyberattacks, Genians reports.

By Indrani Priyadarshini

on August 10, 2026

A North Korean-linked hacking group is developing the capability to use artificial intelligence for more than just creating convincing phishing messages. According to South Korean cybersecurity firm Genians, the group known as Kimsuky has assembled a range of AI tools that could help automate cyberattacks, analyse stolen data and support malware development.

Read More | Cyber-Suraksha.ai: SEBI’s Big Move Against AI-Based Cyberattacks

Genians said it identified infrastructure linked to Kimsuky containing software designed to run and manage artificial intelligence models locally. The tools included Ollama, GPT4All and Msty, along with retrieval-augmented generation (RAG) technology that can be used to search and analyse large collections of documents.

Running AI models locally could give attackers a way to process sensitive or stolen information without sending the data to external AI platforms. This could reduce the risk of exposing their activities to third-party services while allowing them to use AI for analysing large amounts of information.

The cybersecurity firm also identified AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure associated with the campaign. Taken together, these tools suggest that Kimsuky may be exploring ways to integrate AI into different stages of its cyber operations.

Read More | India Expands Cyber Defence Push as Government Orders Sector-Wide Drills Against AI-Powered Cyber Threats

Genians said the activity points to a shift in how Kimsuky is using generative AI. Rather than relying only on AI to create phishing lures, the group appears to be building a broader capability that could support malware development, stolen-data analysis and attack automation.

The company also found finance- and cryptocurrency-themed documents that appeared to have been created using AI. According to Genians, some of the files were designed to resemble legitimate investment reports and workplace documents, potentially making them more convincing to targets.

The findings have not been independently verified. However, North Korean state-linked hacking groups have a long history of cyber espionage, financial theft and other operations aimed at generating revenue for the country. US and South Korean authorities, along with cybersecurity researchers, have repeatedly linked such groups to attacks against organisations and individuals around the world.

Read More | AI Companies Are Buying and Destroying Old Books to Train AI Models, Raising Concerns Over Rare Editions

In 2023, the US Treasury sanctioned Kimsuky, describing it as a North Korean government-controlled cyber-espionage group. The Treasury said the group had gathered intelligence to support Pyongyang’s strategic objectives.

The latest findings highlight a growing concern for cybersecurity teams: AI is not only being used to make cyberattacks more convincing but could increasingly become part of the infrastructure used to plan, develop and automate those attacks.

News Image