Genians logo.

Genians, a cybersecurity firm, said on Sunday that its analysis of the latest attack activity by Kimsuky, a hacking group known to be under North Korea's Reconnaissance General Bureau, found signs it has conducted research and built related technical capabilities to use generative AI-based tools across its overall attack system.

The company said previously identified AI use by North Korean hacking groups mainly focused on the preparation stage, such as forging images and audio and producing phishing lures. But this analysis found traces that went beyond using AI simply to create lures, including the threat actor directly building a local large language model (LLM) execution environment and a retrieval-augmented generation (RAG) environment and operating an AI-based development environment.

It is interpreted as an attempt to analyse stolen documents using a local LLM that can be operated without sending data to an external service, or to automate information extraction and attack tasks.

Specifically, it found signs of building or using local LLM execution and management tools such as Ollama, GPT4All and Msty, as well as RAG configuration environments, AI agent development frameworks and speech-to-text (STT) tools. It also identified many traces of Cursor installation and use, and found records that appear to show documents used in attacks were edited with Cursor and generated outputs were reviewed. Genians explained this is an important case suggesting research and technical validation are under way to use AI for malware development and attack automation.

Attack techniques have also become more sophisticated. While there were many cases of reusing stolen legitimate documents in the past, recently it has been using spearphishing lures in the virtual asset and finance sectors that are believed to have been produced with generative AI. Genians said the approach uses natural writing and a high level of completeness comparable to real work documents to build user trust and induce execution of malicious files.

During the analysis, it also identified signs of attempts to check whether personal data had been exposed, including virtual asset wallet information, Gmail account information and website sign-up history.

Moon Jong-hyun (문종현), head of the Genians Security Center, said, "This analysis is a case showing that a state-backed hacking organisation is building even a local LLM and AI development environment to integrate AI into an actual attack system and is advancing its attack capabilities." He added, "As social engineering attacks are expected to become more sophisticated with advances in AI technology, an EDR-based threat hunting system that detects with a focus on execution behaviour rather than document content is most important."

Keyword

#Genians #Kimsuky #Ollama #GPT4All #Cursor
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.