A North Korean hacking group has created extensive tools for language models and assembled software that could help automate cyberattacks, analyze stolen materials, and create more convincing phishing campaigns, a South Korean cybersecurity company said on Monday, UNN reports, citing Reuters.
Details
Cybersecurity company Genians said it had found evidence that the North Korea-linked Kimsuky group had created tools to run and manage artificial intelligence models locally, including Ollama, GPT4All, and Msty, as well as document-search technology known as retrieval-augmented generation (RAG).
According to the company, these tools could allow operators to process documents without sending sensitive information to third-party AI services.
Genians also found AI-agent development frameworks, speech-to-text software, and Cursor—a tool for AI-assisted programming—on infrastructure linked to the campaign.
The research findings indicate that Kimsuky is moving beyond using generative artificial intelligence to create phishing lures and is expanding its capacity to integrate existing AI models into malware development, data analysis, and attack automation, according to the Genians report.
Genians also said it had found decoy documents on finance and cryptocurrency that appeared to have been created using artificial intelligence. The materials were designed to resemble legitimate investment reports and other work documents, the statement said.
Additional information
North Korea, the publication notes, has for years used state-linked cyber units for espionage, financial theft, and revenue generation, according to U.S. and South Korean authorities, as well as cybersecurity experts.
In 2023, the U.S. Treasury Department imposed sanctions on Kimsuky as a North Korean government-controlled cyberespionage group, saying that it collected intelligence to support Pyongyang’s strategic objectives.
Click Here For The Original Source.
