North Korean spies are running local LLMs to cause AI mischief
Kimsuky's phishing attacks get an AI boost
South Korean security firm Genians detected North Korean spies using local LLMs to conduct AI-enhanced cyber attacks. Kimsuky, a cyber-espionage crew under North Korea's Reconnaissance General Bureau, is integrating AI technology into its attack operations, such as malware development, data analysis, and attack technique advancement.
The researchers observed Kimsuky setting up local LLM environments using Ollama, GPT4All, and Msty, conducting experiments with other AI tools like Cursor, and employing retrieval-augmented generation (RAG) for local document searches. This prevents the data from being transmitted to external AI services, reducing the risk of external exposure.
The North Korean group has collected various libraries, such as LLaMaSharp and Microsoft.Extensions.AI, and packages like OpenAI and Azure.AI.OpenAI, which integrate commercial AI services into their custom applications. While Genians did not find evidence of North Korea training their own models, the findings suggest that the group is developing AI-based tools for specific purposes, rather than simply experimenting with the technology.
Defenders should shift from content-based assessment to behavior-based detection, monitoring for anomalous behaviors following LNK execution, such as PowerShell execution, persistence establishment, and external communications.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- North Korean spies are running local LLMs to cause AI mischief theregister.com