North Korean hacking group Kimsuky expands AI use with local LLM setup | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


A report by a South Korean cybersecurity firm found that Kimsuky was making wider use of the technology while minimizing exposure to detection.

An graphic of a hacker

The North Korean hacking group known as Kimsuky is making use of the localized characteristics of generative AI to automate its hacking attacks and create phishing lures, according to the latest data by a South Korean cybersecurity firm.

Hacking groups linked to Pyongyang had previously used AI mainly in the preparation stages of cyberattacks, but recent activity suggests they are moving toward applying the technology more broadly throughout their operations, according to Genians.

The company detected evidence that Kimsuky had built and operated local large language models (LLM), generative AI models that run directly on users’ own personal computers, laptops or private on-premises servers rather than through a remote cloud service, meaning that the hackers can use AI without having their plans exposed.

Genians found traces of Kimsuky’s activity in logs of locally run LLM applications.

“With a local setup, conversations are not transmitted to external AI services, which reduces the risk of outside exposure,” the firm said. “This makes it a particularly attractive option for state-sponsored threat actors.”

The company also found that Kimsuky continued to carry out spear-phishing attacks — a targeted form of phishing designed to steal personal information from specific individuals — using highly polished lure documents created with generative AI.

Kimsuky has been making frequent use of such lures to create files that resemble professional letters or strategy reports, which carry malicious programs that hack the users’ devices once downloaded. Some companies have been exposed to customer data leaks after downloading files that look similar to their own documents.

A closer analysis of how Kimsuky used AI also revealed numerous characteristics of the North Korean-style use of the Korean language in the group’s logs.


A police officer explains a North Korean attempt to hack the National Police Agency in Seodaemun District, western Seoul, on June 7, 2023.

While attempting to determine whether personal information such as cryptocurrency wallet or email data had been retrieved, Kimsuky used translation software to translate North Korean phrases into English before entering them into AI tools, according to the investigation.

One such request asked the tool to “check whether personal information, including website registration history, has been exposed.” The terms used in the original sentence, corresponding to “website,” “registration history” and “exposed” differ from the South’s standard Korean spellings and expressions.

Genians assessed Kimsuky’s use of AI as part of an effort to automate the creation of lures and hacking operations.

The group, however, does not yet appear to have developed its own AI-powered hacking tools. Rather, it is at the stage of “researching and learning how to incorporate existing AI tools into its attack activities,” Genians said.

The use of AI is increasingly enhancing the capabilities of hacking groups. In May, the global cybersecurity company Kaspersky said it found signs that Kimsuky used AI to develop malware targeting South Korean government systems.

“Kimsuky is researching AI in order to enhance its hacking attacks,” Genians said. “We must stay alert against the development of new attack methods using AI.”

BY IM SOUNG-BIN [shin.woojin@joongang.co.kr]

This article was originally written in Korean and translated by a bilingual reporter with the help of generative AI tools. It was then edited by a native English-speaking editor. All AI-assisted translations are reviewed and refined by our newsroom.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW