North Korea's hackers are leveraging the power of artificial intelligence to launch increasingly sophisticated cyberattacks, according to a recent report by South Korean cybersecurity firm Genians. This development is particularly concerning given the nation's history of cyber aggression and the potential for AI to lower the barrier to entry for malicious actors.
The report highlights the activities of the Kimsuky hacking group, which has been using AI-generated documents in spear-phishing attacks since 2026. By automating the creation of malicious files disguised as legitimate documents, Kimsuky has been able to evade detection and launch attacks with greater efficiency. This shift in tactics demonstrates the evolving nature of cyber threats and the importance of staying vigilant against new attack vectors.
The use of open-source tools like Ollama, GPT-4All, and Msty allows Kimsuky to run large language models without an internet connection, further enhancing their ability to remain undetected. As AI continues to advance, the potential for harm by bad actors and systems going rogue becomes increasingly significant.
The implications of this development are far-reaching. North Korean hackers have already stolen cryptocurrency worth over $2 billion in the first nine months of 2025, and their involvement in the 2014 Sony Pictures hack is well-documented. The ability to automate and scale social engineering attacks using AI could lead to even more devastating consequences in the future.
Jenny Town, a senior fellow at the Stimson Center in Washington, DC, emphasizes the capabilities of North Korean hackers and programmers in utilizing AI tools. She notes that North Korea is not an exception in this new reality of threat actors leveraging AI for their malicious activities.
The rise of AI-supported cyberattacks is a significant challenge for the decade ahead. Mark T. Hofmann, a criminal and intelligence analyst, warns that the dark side of AI will become a regular phenomenon, requiring enhanced cybersecurity measures and a proactive approach to mitigate the risks associated with this rapidly evolving technology.