North Korea-linked hackers turn to AI agents for malicious email decoys | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A South Korean security firm said the hacking group Kimsuky used an open-source AI coding agent to create documents that concealed malware.

This rendered image illustrates a North Korea-linked hacker

North Korea-linked hacking group Kimsuky was found to have leveraged AI coding agents to create decoys for malicious code, a local security firm said Monday.

Such findings were detected after an analysis of 13 malicious files collected last month, Genians said in its latest cybersecurity threat intelligence report.

According to the report, researchers found that the hacking group distributed emails with attached compressed files containing documents titled “insurance bills” or “policy fund notice.” They activated malware when users clicked them, the report said.

The files contained traces of being created by an open-source AI coding agent called opencode.

“In some of the PDF documents, both the ‘creator’ and ‘producer’ fields in the metadata were listed as ‘opencode,'” the report said.

“These are not values typically generated with standard document creation software, strongly suggesting the documents were generated by an AI agent through programming, rather than created manually.”

Genians said it marks the first time the company has detected signs that Kimsuky is using AI coding agents in its malicious attacks.

Earlier, the company said it detected signs of the hacking group using large language models to create decoys and plan malicious attacks.

Yonhap



Click Here For The Original Source.

——————————————————–

..........

.

.