North Korea-linked hackers are moving beyond crude phishing and into local AI setups that help them work faster, hide better, and hit crypto firms with more precision. South Korean cybersecurity firm Genians says Kimsuky has been using offline AI tooling to support malware work, data analysis, and phishing operations, while other North Korea-linked crews keep sharpening the same playbook against the crypto industry.
- Local AI, not cloud hype: Genians says Kimsuky used Ollama, GPT4All, and Msty to run AI tools on its own systems.
- Real operational use: The setup reportedly supported malware development, analysis, and attack automation.
- Crypto remains a bullseye: North Korea-linked thefts in 2025 were estimated at $2.02 billion, according to Chainalysis data cited by crypto.news.
- Attackers are getting slicker: Fake meetings, lookalike domains, insider-style access, and AI-written lures are now all part of the same ugly toolkit.
The key distinction is simple: Genians did not find evidence that Kimsuky was training its own proprietary AI models from scratch. What it did find was something more practical and arguably more dangerous, existing AI tools wired into an attack workflow that helps with reconnaissance, phishing, and code-related work. Its AI-Driven Decoy Documents and Threat Actor Analysis lays out the technical details behind that assessment.
That is the part security teams should care about. Not some sci-fi fantasy of a North Korean supercomputer, but a duller and far more believable reality: attackers using off-the-shelf AI to make their scams cleaner, faster, and harder to spot.
According to Genians, Kimsuky built local AI environments using Ollama, GPT4All, and Msty. Running models locally means the tools operate on the group’s own machines instead of through third-party cloud services. That matters because it can reduce exposure, limit logging, and make the setup less visible to outside defenders.
The environments reportedly supported retrieval-augmented generation, or RAG. In plain English, that means the operator can feed the model specific files, notes, or templates so it produces output that sounds tailored instead of generic. For phishing and social engineering, that is a gift wrapped in malware. A separate report on North Korean hacking group builds AI tools for cyberattacks points to the same trend from another angle.
Genians also said it found libraries and frameworks that can embed language models into custom software, along with Cursor and speech-to-text tools. Taken together, that points to more than a few random experiments. The firm said the activity appeared to have moved beyond isolated tests and into support for malware development, data analysis, and attack automation.
The phishing side was just as telling. Genians said Kimsuky used generative AI to create material targeting cryptocurrency, investment strategies, and fintech services. Researchers also found documents that closely copied material linked to a Korean AI-powered investment platform. That kind of forgery is exactly where AI shines for criminals: not brilliance, just enough polish to fool a rushed human.
Kimsuky is not alone in this. Another North Korea-linked crew, BlueNoroff, has been pushing a different but related scam style. In July, JUMPSEC reported that BlueNoroff used fake Zoom and Microsoft Teams meetings to profile crypto users before delivering malware.
That report got unusually concrete because the researchers recovered source code from an active phishing kit after the operators exposed JavaScript source maps. Source maps are development files that can reveal how a website or script is built behind the scenes. In this case, they exposed wallet-scanning functions, operator controls, and separate malware delivery paths for Windows and macOS.
The fake-meeting setup checked for Ethereum wallet connections and non-EVM wallets, including Solana tools. Windows implants could identify browser extensions across Chrome, Edge, Brave, Opera, Vivaldi, and Firefox variants, which let the attackers look for wallets such as MetaMask. That is not random spam. It is victim profiling with a lot of patience and a very sharp knife.
Arctic Wolf added more texture to that campaign by identifying more than 80 lookalike Zoom and Teams domains tied to related operations. About 80% of the targets Arctic Wolf identified worked in crypto, blockchain finance, or connected investment sectors. Founders and chief executives made up 45% of the identified targets.
That target mix says a lot. The attackers are not just fishing for anyone with a browser. They are hunting people with access, authority, and usually one too many reasons to click fast.
The threat does not stop at phishing kits and fake meetings. In July, Consensys temporarily stopped product releases after discovering a North Korea-linked consultant had access to its systems for roughly one month, according to Drop Site News. The consultant used the name Tyler Knapp and the GitHub handle “imyugioh.”
He reportedly contributed to core MetaMask platform code, including parts connecting users with third-party fiat payment providers. Consensys general counsel Matt Corva said a third-party service provider introduced the consultant. Consensys later said its investigation found no stolen assets or data, no malicious code, and no impact on user security.
That does not make the incident trivial. Even without stolen funds or malicious code, suspicious contractor access can trigger audits, emergency reviews, release delays, and a pile of trust damage. In cybersecurity, sometimes the attack is the disruption itself.
The broader infiltration picture is just as ugly. The Ketman Project identified about 100 suspected North Korean IT workers using false identities across 53 crypto and Web3 projects. Investigators traced them across 11 code repositories where projects had already merged 62 pull requests before detection.
That is a real footprint inside real projects. It suggests a long game: blend in, contribute code, earn trust, and only then exploit access or intelligence. Digital raccoons with GitHub accounts, basically, except these ones may be state-backed.
Then there is the money, which is why this keeps happening. North Korea-linked hacking groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data previously reported by crypto.news. Most of those losses came from the February 2025 hack of Bybit, and North Korean Hackers Tied to Record $635M Crypto Theft in was another reminder of how quickly the damage can snowball.
In that breach, more than 400, 000 Ether and staked Ether worth about $1.5 billion were stolen. The FBI attributed the attack to North Korea and identified the actors under its TraderTraitor designation.
On Aug. 8, Bybit sued the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency, and the Lazarus Group in the U.S. District Court for the District of Columbia. The exchange also obtained a preliminary injunction covering certain stolen assets held by unidentified defendants. U.S., Japan, South Korea Tackle North Korea’s $659M Crypto shows how governments are also trying to push back.
By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked. That does not mean the rest was neatly recovered. It means a large chunk had already gone into the usual laundering maze of mixers, bridges, shell wallets, and chain-hopping. Crypto’s transparency stops being cute very quickly when criminals start using it like a relay race.
AI is making that race harder for defenders. Illia Polosukhin, co-founder of NEAR Protocol, said AI is increasing hackers’ ability to find vulnerabilities faster than conventional security can patch them. That fits the broader pattern here: faster lure generation, faster target sorting, faster code adaptation, faster reconnaissance.
There is also a caution flag around the idea that AI is magically responsible for every big exploit now. The suspected $100 million Coldcard Bitcoin hardware wallet exploit has been mentioned by some observers in the context of an obscure vulnerability allegedly uncovered with AI, but that remains a suspicion, not a settled fact. Useful context, yes. Proven attribution, no.
The real takeaway is more grounded and more worrying. North Korea-linked operators are not just using AI for a few shiny phishing emails. They appear to be folding local AI into an operational workflow that helps with malware work, data triage, lure generation, and target selection. That is a lot more serious than a spam bot with grand ambitions.
Key questions and takeaways
-
Is Kimsuky building its own AI models from scratch?
No. Genians did not find evidence of proprietary model training. The concern is the use of existing AI tools in a local, operational setup. -
Why do local AI environments matter?
They keep AI activity off external cloud services, which can make it harder to monitor, disrupt, or trace. -
What is retrieval-augmented generation?
It lets attackers feed an AI their own documents, notes, or templates so the output sounds more specific and convincing. -
How are North Korea-linked groups targeting crypto users?
Through fake meetings, phishing pages, lookalike domains, wallet scanning, insider-style access, and malware delivery built to match the victim’s device. -
How big is the North Korea-linked crypto theft problem?
Very big. Chainalysis data cited by crypto.news put 2025 losses at an estimated $2.02 billion, with the Bybit breach making up most of that total. -
Are crypto firms still a prime target?
Yes. The reporting points to crypto, blockchain finance, and connected investment sectors being heavily targeted, especially founders and executives. -
What should crypto companies take from this?
Tighten contractor screening, lock down third-party access, harden phishing defenses, verify meeting links and wallet prompts, and assume social engineering will keep getting more convincing.
The pattern is no longer subtle. Crypto firms are still being hunted because the payoff is huge, the targets are remote, and human error remains the easiest exploit of all. Add local AI to the mix and the operation gets cheaper, faster, and harder to see coming. The defenders are improving too, but so are the people trying to empty the wallets.
Further reading
For a deeper look at the scale of North Korea-linked crypto thefts and how they’re evolving, this follow-up is worth a look: