North Korea’s hackers are building their own AI tools to dodge the guardrails

Researchers say the state-linked group Kimsuky is running open models on its own machines, automating phishing and malware while staying out of sight of commercial AI providers.


North Korea’s hackers are building their own AI tools to dodge the guardrails

North Korea’s hackers have found a way to harness AI without ever handing their secrets to a Silicon Valley company. According to the South Korean cybersecurity firm Genians, the state-linked group Kimsuky has been building its own AI tools to automate and sharpen its cyberattacks.

The clever part is how deliberately it stays off the grid. Rather than lean on commercial chatbots, which log activity and screen for abuse, the group is running open models such as Ollama, GPT4All and Msty directly on its own machines, which keeps sensitive work away from any provider that might notice or report it.

That choice is the whole strategy in miniature. By keeping everything local, Kimsuky sidesteps the monitoring and safety filters that firms like OpenAI have built precisely to catch this kind of misuse, turning freely available AI software into an in-house weapon nobody else can see running.

The toolkit goes well beyond a chatbot, too. Genians says the group has pulled in retrieval-augmented generation to sift stolen documents, AI agent frameworks to string tasks together, speech-to-text software, and even Cursor, the AI-assisted coding tool, to help write and refine its malware.

With that stack in hand, the group can work faster and more convincingly across the board. The researchers describe it automating attacks, crafting more believable phishing lures, weaving AI into malware development, and analysing whatever it steals, all without the bottleneck of doing each step by hand.

The deception has become notably slicker as a result. Among the group’s outputs are finance- and cryptocurrency-themed documents designed to mimic legitimate workplace reports, the sort of polished bait that is far harder to dismiss than the clumsy phishing of years past.

None of this comes out of nowhere, because Kimsuky is a known and sanctioned operator. The US Treasury blacklisted it back in 2023, describing it as a North Korean government-controlled cyber-espionage group that gathers intelligence to serve Pyongyang’s strategic aims.

The group also fits a long pattern of North Korean cyber activity aimed at money and secrets alike. Pyongyang’s crews have repeatedly gone after developers and crypto users, including poisoned code packages built to steal developer credentials, and AI simply makes those campaigns cheaper to run at scale.

The regime’s hackers are, in effect, a state enterprise. Washington has sanctioned several North Korean groups behind attacks such as WannaCry, reflecting how central cybercrime has become to a heavily isolated economy in need of hard currency.

What makes the AI angle worrying is how it lowers the cost of scale. The same automation is helping fuel a wider surge in online crime, with the global scam economy passing $442bn, and a well-resourced state actor is far better placed to exploit these tools than a lone fraudster.

It also feeds a thornier question the industry has yet to answer. As autonomous software takes on more of the work, it remains unsettled who is accountable when an AI agent causes harm, and a hostile government running its own models sits well outside any provider’s reach in the first place.

One caveat is worth keeping in view. Genians’ findings could not be independently verified, so the precise scope of the operation rests on a single firm’s research, even if it aligns with everything known about the group.

It also complicates the case that open models are harmless by default. The very openness that lets researchers and startups build freely is what lets a sanctioned state run the same software beyond anyone’s reach, a trade-off the industry has been reluctant to confront head-on.

The broader lesson is uncomfortable all the same. The safety controls that leading labs tout work only when the misuse runs through them, and by choosing open models on private hardware, the world’s most determined attackers have found the obvious way around them.

Get the TNW newsletter

Get the most important tech news in your inbox each week.