The South Korean cybersecurity firm Genians has stated that it has detected artificial intelligence tools on infrastructure linked to the North Korean group Kimsuky. These tools may help to automate the analysis of stolen documents, the preparation of phishing materials and certain stages of cyberattacks. The researchers do not rule out the possibility that some of the programmes are merely being tested.
Briefly about the main points
- Genians links the AI infrastructure it has identified to the Kimsuky group.
- Local models allow you to process stolen files without using cloud services.
- RAG can speed up the search for the required data within large collections of documents.
- Cursor, AI agents and speech recognition tools were found on the infrastructure.
- Not all of the tools identified have been confirmed as having been used in actual attacks.
Local models for processing sensitive data
According to Genians, the Kimsuky operators have set up an environment for running and managing large language models on their own systems. The software identified includes Ollama, GPT4All and Msty, as well as retrieval-augmented generation (RAG) technology.
This approach means that documents do not need to be transferred to external cloud-based AI services. This may be important for attackers when working with files containing confidential information: the data remains within the infrastructure they control.
Faster searching of stolen documents
RAG gives the language model access to its own document repository and helps it find the required information within it. Once they have gained access to a computer or corporate network, attackers can obtain large volumes of correspondence, spreadsheets, archives and other files, which previously had to be reviewed largely by hand.
Artificial intelligence It is potentially capable of sorting through materials, searching for surnames and contact details, identifying financial or confidential information, finding references to companies or projects, and summarising large datasets concisely. Genians describes the automation of such analysis as one of the potentially most dangerous ways in which AI could be used by criminal groups.
Tools for code, agents and speech processing
The researchers also discovered the Cursor AI code editor, frameworks for creating AI agents, and software for converting speech to text. According to Genians, these findings may indicate that AI is being experimented with not only in text-based tasks, but also in the development of malicious software and the automation of specific actions during an attack.
In theory, an AI agent could process the collected data sequentially, draft new phishing text, adapt the code or generate materials for the next stage of the operation. The company does not claim that Kimsuky has already put such scenarios into practice.
Financial lures for phishing campaigns
Genians has uncovered decoy financial and cryptocurrency documents which, according to the researchers’ assessment, may have been created using AI. These were disguised as investment reports and working financial documents that company employees might share as part of their day-to-day work.
Documents of this kind can be used in phishing campaigns, with a malicious file or link attached to them. Generative AI makes it possible to create large quantities of such material more quickly and tailor it to a specific individual or organisation.
Limitations of the findings and the context of Kimsuky’s activities
Genians emphasises that not all of the tools discovered are necessarily already being used to their full potential in real-world attacks: some may still be at the development or testing stage. The South Korean company’s technical findings have not been independently verified.
Kimsuky is considered one of the most active North Korean cyber groups and is linked to intelligence operations on behalf of the DPRK regime. In 2023, the US Department of the Treasury imposed sanctions on the group, designating it as a cyber-espionage group controlled by the DPRK government. Genians’ findings may indicate a shift from using individual generative services to deploying on-premises AI infrastructure.







