DigitalMoneyBox Signal Desk
DigitalMoneyBox Crypto market intelligence
Browse sections
Research CryptoNinjas

North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks

Key Takeaways: Kimsuky was using Ollama, GPT4All and Msty, three local LLM environments. Crypto, financial and investment targets are being scammed using AI-generated documents. The group remains using LNK files, and Pow...

66 /100
Market signal

Watchlist

Published in the last two hours. It maps to a high-priority topic hub.

North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks

Key Takeaways:

  • Kimsuky was using Ollama, GPT4All and Msty, three local LLM environments.
  • Crypto, financial and investment targets are being scammed using AI-generated documents.
  • The group remains using LNK files, and PowerShell and GitHub based infrastructure.

User Score

8.7

Follow us on Google News

North Korea-linked hacking group Kimsuky is moving deeper into artificial intelligence, with new research showing the attackers are building local AI environments and using generative tools in campaigns targeting cryptocurrency and financial-sector users.

South Korean cybersecurity firm Genians said the activity is part of Kimsuky’s broader attack operations rather than a standalone campaign. The researchers track the activity as Operation GitPower, which builds on tactics previously associated with the FlowerPower campaign.

Kimsuky Builds Local AI Infrastructure

Genians found that Ollama, GPT4All and Msty were tools used to run Kimsuky local LLM environments. The group was also seen exploring technologies such as retrieval-augmented generation (RAG) and the AI coding assistant Cursor.

The results indicate that Kimsuky does not rely on public AI chatbots just for occasional tasks. Rather, the community seems to be gearing up for integrating AI into various segments of the attack process.

By running AI models locally, attackers can also gain more control over the data and operations they use. Sensitive questions, program development and information collected can be analyzed without strict dependence on third-party cloud AI services.

Genians stated that evidence suggests it is an era of developing capabilities, in which AI may be used to aid in the creation of malware, information analysis as well as information automation in attacks.

Read More: $290M KelpDAO Hack SHOCK: LayerZero Points to Fatal DVN Flaw, Lazarus Suspected

AI-Generated Documents Target Crypto Users Polished Lures Replace Crude Phishing

The most obvious shift is that of Kimsuky’s phishing materials.

Genians discovered content logs regarding virtual assets, financial investment, and game development with indications of content generation involving AI. The documents were professionally organized, in natural language, very similar to real business letters.

Researchers also found metadata is associated with certain English-language documents that link them to python-docx or WPS Office, and the documents’ creation and modification dates had surprisingly regular patterns. The results were evaluated for its implication of an automated document production process.

In yet another campaign, a malicious LNK file was disguised as an investment strategy document. The lure was similar to a Korean fintech site, making it more likely that potential victims would believe what was being sent.

Crypto Targets Remain in the Crosshairs

Kimsuky continues to attack organisations and professionals related to virtual assets, finance, diplomacy, security and international affairs.

The technical delivery chain remains familiar. The victim then gets the malicious LNK shortcuts packaged as valid archives and in ZIP format. When run, the files can unhide any command-line instructions or PowerShell loaders.

Defenders were advised to stay vigilant for any unusual execution arguments to the LNK, PowerShell arguments hidden in files, scheduled tasks, access to GitHub Raw Contents API, use of unusual personal access tokens, or .data (encrypted) arguments.

Read More: $18M Ostium Vault Exploit Drains Arbitrum Protocol

The post North Korean Hackers Deploy 3 Local AI Systems to Supercharge Crypto Attacks appeared first on CryptoNinjas.

Why this matters

This maps to the Security Incidents hub, so it can help confirm whether that theme is gaining breadth across the crypto news cycle.

Original source

Read on CryptoNinjas

Related market context