North Korea-linked Kimsuky group accused of using AI in spear-phishing attacks

North Korea-linked Kimsuky group accused of using AI in spear-phishing attacks

A South Korean cybersecurity firm says the North Korea-linked hacking group Kimsuky has been using artificial intelligence to support spear-phishing attacks against military, diplomatic and academic targets. The report says the group has been creating malicious files disguised as legitimate documents, including research reports and invitations. It says the activity has been taking place since 2026.

Orovi_landscape

Sponsored

The firm, Genians, said the group has used AI-generated documents in a pattern of attacks and has relied on offline tools including Ollama, GPT-4All and Msty. According to the report, those tools allow large language models to run without an internet connection, which can make detection more difficult. Genians said the shift goes beyond changing how decoy documents are made and shows how AI can help automate and scale social engineering attacks.

The report adds to long-running concerns about North Korea-linked cyber activity, which has previously been associated with espionage and financially motivated attacks. Kimsuky has been linked by investigators to North Korea's intelligence services, and the group has been named in past reporting on cyber operations against foreign targets. The latest allegation suggests a further evolution in tactics, with AI being used to increase the speed and polish of phishing material.

The development matters because military, diplomatic and academic institutions are often targeted for information that can be useful for intelligence gathering. AI-assisted phishing can make fraudulent messages and attachments more convincing, increasing the risk that recipients will open them. It can also reduce the time needed to produce large numbers of tailored lures, which may widen the scale of attempted intrusions.

Santuzza_land

Sponsored

The report comes amid wider debate over how quickly generative AI tools are being adopted by malicious actors. It also follows earlier warnings that North Korean hackers have repeatedly adapted their methods as cyber defences improve. The firm's findings suggest that offline AI tools may be attractive to threat actors because they can be used without exposing activity to internet-based monitoring.

What remains unclear is how many successful intrusions, if any, resulted from the campaign described in the report. The firm's findings describe a pattern of activity, but they do not provide a full public accounting of the damage or the identities of all intended victims. Further disclosures from investigators or affected institutions may clarify the scale of the operation and whether the tactics are being copied elsewhere.

360LiveNews 360LiveNews | 10 Aug 2026 09:30 LONDON
← Back to Homepage