Skip to main content
Back to News
Genians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) ha...
Technology
2 min read
KR

Genians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) ha...

The AMW Read

The report reveals a new pattern of state-sponsored AI adoption in cyber attacks, updating the threat landscape for the security segment.
NoveltySignificance
Finance & Ops · Player Map
Genians
Genians

AI in Cybersecurity

View Company Profile

Genians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) has been setting up local AI infrastructure, including local large language models (LLMs) and AI development environments, to automate attacks. The analysis found traces of tools like Ollama, GPT4All, and Msty, along with retrieval-augmented generation (RAG) setups, AI agent frameworks, and speech-to-text tools. The group also used Cursor, an AI-powered code editor, to edit documents and review AI-generated outputs, indicating research into using AI for malware development and attack automation. However, Genians clarified that the evidence supports preparation and tooling, not full autonomous attack execution.

This development signals a shift in how state-sponsored actors are operationalizing AI: moving from using AI for phishing content to embedding AI into their attack chain. By running local LLMs and RAG, these groups avoid sending data to external AI services, reducing detection and maintaining control. The use of Cursor suggests that AI coding assistants are being adopted not just by developers but also by threat actors, potentially accelerating the creation of sophisticated malware. This could heighten the risk for enterprises, as AI-generated documents and automated analysis make social engineering more convincing and harder to detect.

For builders and investors in the AI security space, this underscores the importance of behavior-based detection (like EDR) over content analysis, as AI can craft near-perfect lures. Startups focusing on AI-driven threat hunting and anomaly detection may find growing demand. For enterprises, the lesson is to assume that phishing emails and attachments may be AI-crafted, and to prioritize security training and endpoint monitoring. The sharing of these findings with KISA and international partners highlights the need for collaborative threat intelligence in the AI era.

#AIsecurity #NorthKorea #CyberThreats #LLM #EDR #Genians

#Genians#Kimsuky#North Korea#AI security#local LLM

How This Connects

Based on Finance & Ops · Player Map

  1. 1d agoGenians, a South Korean security firm, reported that the North Korean hacking group Kimsuky (김수키) ha... · THIS ARTICLE
  2. 1d agoAstraeus, a New York-based startup, has raised over $10 million to launch an AI-native infrastructur...Astraeus
  3. 1w agoMicrosoft has announced Project Perception, a new AI-powered cybersecurity platform that uses multip...
  4. 1mo agoMicrosoft launches its own AI deployment company with $2.5 billion commitment

More news from Genians

Stay updated with the latest news and announcements from Genians.

View all Genians news

Discover AI Startups

Explore 5,000+ AI companies with VC-grade analysis, funding data, and investment insights.

Explore Dashboard