Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

North Korean Spies Utilize Local AI to Compromise Global Networks



North Korean spies have been using local Large Language Models (LLMs) to enhance their AI-based phishing attacks, according to a recent report from Genians. The Reconnaissance General Bureau's (RGB) cyber-espionage crew, Kimsuky, has been leveraging these LLMs to create more convincing and targeted decoy documents, making it increasingly difficult for organizations to detect and respond to these threats.

  • Kimsuky, a North Korean cyber-espionage crew, has been using local Large Language Models (LLMs) in its phishing attacks, creating more convincing and targeted decoy documents.
  • The LLMs are used to create ZIP archives containing malicious LNK files disguised as international event materials or research reports.
  • Kimsuky uses AI to create lures related to virtual assets and finance, increasing user trust with natural language, polished structure, and formats similar to actual business materials.
  • The threat actor employs various obfuscation techniques, including Base64 encoding and custom decoding routines, to evade detection.
  • Kimsuky uses Git repositories for command-and-control (C2) infrastructure, adapting their tactics to make them increasingly difficult to detect.
  • The use of local LLMs by Kimsuky marks a significant escalation in the threat landscape, enabling North Korean spies to cause AI mischief while minimizing their exposure to external detection.



  • The nefarious tactics employed by North Korean spies have once again come to light, as a recent report from Genians, a South Korean security firm, reveals that the Reconnaissance General Bureau (RGB) has been using local Large Language Models (LLMs) to enhance their AI-based phishing attacks. This new development underscores the evolving threat landscape and the need for organizations to stay vigilant in the face of increasingly sophisticated cyberattacks.

    Kimsuky, a well-documented cyber-espionage crew operating under the RGB, has long been known for its phishing campaigns targeting government agencies, think tanks, academia, and security research organizations. However, the latest findings suggest that Kimsuky has taken its attacks to the next level by leveraging local LLMs to create more convincing and targeted decoy documents.

    According to Genians' report, Kimsuky uses ZIP archives containing malicious LNK files, which are often disguised as materials related to international events, research reports, or meeting requests. When an unsuspecting recipient opens the archive and executes the LNK file, a PowerShell loader is activated, allowing the attackers to collect system information and assess the infected environment.

    In some cases, Kimsuky has employed AI to create lures related to virtual assets and finance, using natural language, polished structure, and formats similar to actual business materials to increase user trust. These decoy documents are designed to induce the execution of malicious files, further underscoring the sophisticated nature of these attacks.

    To evade detection, Kimsuky has employed various obfuscation techniques, including Base64 encoding, string splitting, and custom decoding routines. This enables them to hide the malicious behavior of their files and maintain a low profile.

    Genians' researchers also observed that Kimsuky uses Git repositories for command-and-control (C2) infrastructure, with multiple public GitHub repositories operated by the threat actor containing configuration files, PowerShell scripts, and various payloads used in subsequent attacks. This highlights the threat actor's ability to adapt and evolve their tactics, making them increasingly difficult to detect.

    Furthermore, Genians uncovered evidence of Kimsuky's use of local LLM environments, including Ollama, GPT4All, and Msty, which are used for experimentation with other AI tools such as Cursor and retrieval-augmented generation (RAG) for local document searches. This approach prevents the data from getting sucked into the cloud, reducing the risk of external exposure and making it a particularly attractive option for a state-sponsored threat actor.

    In addition to their phishing campaigns, Kimsuky has also been collecting a large number of libraries and packages, including LLaMaSharp and Microsoft.Extensions.AI, which call and integrate commercial AI services into their own custom applications. This suggests that the threat actor is not only developing its own AI-based tools but also leveraging external resources to enhance its capabilities.

    Genians' findings provide concrete evidence that Kimsuky-affiliated threat actors are moving beyond one-off experimentation with AI and are continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques. This highlights the need for defenders to shift away from content-based assessment to behavior-based detection and emphasizes the importance of staying vigilant in the face of evolving threats.

    The use of local LLMs by Kimsuky marks a significant escalation in the threat landscape, as it enables North Korean spies to cause AI mischief while minimizing their exposure to external detection. As organizations continue to rely on AI-powered systems, they must also be aware of the potential risks associated with these technologies and take proactive measures to protect themselves against such threats.

    In conclusion, the recent report from Genians has shed light on the sophisticated tactics employed by Kimsuky in their use of local LLMs. This highlights the need for organizations to stay vigilant and adapt their security strategies to counter the evolving threat landscape.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/North-Korean-Spies-Utilize-Local-AI-to-Compromise-Global-Networks-ehn.shtml

  • https://www.theregister.com/security/2026/08/10/north-korean-spies-are-running-local-llms-to-cause-ai-mischief/5285632


  • Published: Mon Aug 10 14:49:07 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us