Urgent.News

What's breaking now, across thousands of outlets.

AI

North Korean hacking group builds AI tools for cyberattacks, report says

The group reportedly collected software that could help automate cyberattacks, analyze stolen material and produce better phishing campaigns.

North Korean hacking group builds AI tools for cyberattacks, report says

Seoul – A South Korean cybersecurity firm has uncovered evidence that a North Korean hacking group, Kimsuky, has developed artificial intelligence tools for cyberattacks, document analysis and phishing campaigns. The firm, Genians, discovered Kimsuky had set up local infrastructure to manage and run AI models such as Ollama, GPT4All and Msty, alongside retrieval augmented generation technology.

The tools, according to Genians, could enable operators to process sensitive documents without sending them to external AI services. The company also found AI agent development frameworks, speech-to-text software and an AI-assisted coding tool called Cursor on the infrastructure linked to Kimsuky's operations. These findings suggest that Kimsuky is moving from using AI to generate phishing lures to integrating existing AI models into malware development, data analysis and attack automation.

Additionally, Genians found finance and cryptocurrency-themed decoy documents that appeared to be AI-generated, designed to mimic legitimate investment reports and workplace documents. However, these findings cannot be independently verified, and North Korea has a history of using state-linked cyber units for espionage, financial theft and revenue generation.

In 2023, the U.S. Treasury sanctioned Kimsuky as a North Korean government-controlled cyber-espionage group due to its role in gathering intelligence in support of Pyongyang’s strategic objectives.

Written by urgent.news from Japan Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at japantimes.co.jp →

More in AI

Can you run a GNN without anyone seeing the data? Journal of our experiments on privacy-preserving GNN inference on microcontrollers

I have been keenly interested in how to make Graph Neural Networks (GNN) run securely on resource-constrained devices. The question driving this work is deceptively simple: can three microcontrollers…

  • Researchers demonstrate privacy-preserving GNN inference on microcontrollers
  • Graph topology public, only node features and model weights protected
  • Secure matrix multiplication handled via Replicated Secret Sharing

More from Monday 10 August →