
Genians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) ha...
The AMW Read
The report reveals a new pattern of state-sponsored AI adoption in cyber attacks, updating the threat landscape for the security segment.
Genians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) has been setting up local AI infrastructure, including local large language models (LLMs) and AI development environments, to automate attacks. The analysis found traces of tools like Ollama, GPT4All, and Msty, along with retrieval-augmented generation (RAG) setups, AI agent frameworks, and speech-to-text tools. The group also used Cursor, an AI-powered code editor, to edit documents and review AI-generated outputs, indicating research into using AI for malware development and attack automation. However, Genians clarified that the evidence supports preparation and tooling, not full autonomous attack execution.
This development signals a shift in how state-sponsored actors are operationalizing AI: moving from using AI for phishing content to embedding AI into their attack chain. By running local LLMs and RAG, these groups avoid sending data to external AI services, reducing detection and maintaining control. The use of Cursor suggests that AI coding assistants are being adopted not just by developers but also by threat actors, potentially accelerating the creation of sophisticated malware. This could heighten the risk for enterprises, as AI-generated documents and automated analysis make social engineering more convincing and harder to detect.
For builders and investors in the AI security space, this underscores the importance of behavior-based detection (like EDR) over content analysis, as AI can craft near-perfect lures. Startups focusing on AI-driven threat hunting and anomaly detection may find growing demand. For enterprises, the lesson is to assume that phishing emails and attachments may be AI-crafted, and to prioritize security training and endpoint monitoring. The sharing of these findings with KISA and international partners highlights the need for collaborative threat intelligence in the AI era.