North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks
Key Takeaways: Kimsuky was using Ollama, GPT4All and Msty, three local LLM environments. Crypto, financial and investment targets are being scammed using AI-generated documents. The group remains using LNK files, and Pow...
Watchlist
Published in the last two hours. It maps to a high-priority topic hub.
Key Takeaways:
- Kimsuky was using Ollama, GPT4All and Msty, three local LLM environments.
- Crypto, financial and investment targets are being scammed using AI-generated documents.
- The group remains using LNK files, and PowerShell and GitHub based infrastructure.
User Score
8.7
Follow us on Google NewsNorth Korea-linked hacking group Kimsuky is moving deeper into artificial intelligence, with new research showing the attackers are building local AI environments and using generative tools in campaigns targeting cryptocurrency and financial-sector users.
South Korean cybersecurity firm Genians said the activity is part of Kimsuky’s broader attack operations rather than a standalone campaign. The researchers track the activity as Operation GitPower, which builds on tactics previously associated with the FlowerPower campaign.
Kimsuky Builds Local AI InfrastructureGenians found that Ollama, GPT4All and Msty were tools used to run Kimsuky local LLM environments. The group was also seen exploring technologies such as retrieval-augmented generation (RAG) and the AI coding assistant Cursor.
The results indicate that Kimsuky does not rely on public AI chatbots just for occasional tasks. Rather, the community seems to be gearing up for integrating AI into various segments of the attack process.
By running AI models locally, attackers can also gain more control over the data and operations they use. Sensitive questions, program development and information collected can be analyzed without strict dependence on third-party cloud AI services.
Genians stated that evidence suggests it is an era of developing capabilities, in which AI may be used to aid in the creation of malware, information analysis as well as information automation in attacks.
Read More: $290M KelpDAO Hack SHOCK: LayerZero Points to Fatal DVN Flaw, Lazarus Suspected
AI-Generated Documents Target Crypto Users Polished Lures Replace Crude PhishingThe most obvious shift is that of Kimsuky’s phishing materials.
Genians discovered content logs regarding virtual assets, financial investment, and game development with indications of content generation involving AI. The documents were professionally organized, in natural language, very similar to real business letters.
Researchers also found metadata is associated with certain English-language documents that link them to python-docx or WPS Office, and the documents’ creation and modification dates had surprisingly regular patterns. The results were evaluated for its implication of an automated document production process.
In yet another campaign, a malicious LNK file was disguised as an investment strategy document. The lure was similar to a Korean fintech site, making it more likely that potential victims would believe what was being sent.
Crypto Targets Remain in the CrosshairsKimsuky continues to attack organisations and professionals related to virtual assets, finance, diplomacy, security and international affairs.
The technical delivery chain remains familiar. The victim then gets the malicious LNK shortcuts packaged as valid archives and in ZIP format. When run, the files can unhide any command-line instructions or PowerShell loaders.
Defenders were advised to stay vigilant for any unusual execution arguments to the LNK, PowerShell arguments hidden in files, scheduled tasks, access to GitHub Raw Contents API, use of unusual personal access tokens, or .data (encrypted) arguments.
Read More: $18M Ostium Vault Exploit Drains Arbitrum Protocol
The post North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks appeared first on CryptoNinjas.
Why this matters
This maps to the Security Incidents hub, so it can help confirm whether that theme is gaining breadth across the crypto news cycle.
Original source
Read on CryptoNinjasRelated market context
North Korea’s Kimsuky integrates AI into cyberattacks targeting crypto and finance
Kimsuky uses generative AI to produce phishing documents themed around digital assets, investment strategies, and fintech services...
Why crypto ‘audited’ badges are giving investors a dangerous false sense of security
At 1:30 p.m. UTC on Feb. 21, 2025, Bybit began moving funds from an Ethereum cold wallet to a warm wallet, the sort of routine tra...
Syntetika Launches Tokenization Hub Bringing Regulated Investment Strategies Onchain
Road Town, British Virgin Islands, August 10th, 2026, Chainwire Deposits Are Open for hBTC, the Vault Token for Hilbert Group’s BT...
H100 Group becomes 26th-largest Bitcoin treasury company after acquiring two European firms
H100 Group's strategic acquisitions highlight Europe's growing influence in the corporate Bitcoin treasury market, challenging Nor...
This $1.5 billion hack is exposing just how ‘irreversible’ stolen crypto really is
Bybit sued North Korea, its Reconnaissance General Bureau, and Lazarus Group in the US District Court for the District of Columbia...
H100 Group completes world’s first Bitcoin-for-Bitcoin M&A deal
This groundbreaking Bitcoin-only M&A deal highlights a shift towards cryptocurrency in corporate finance, potentially influencing...