South Korean cybersecurity firm Genians has announced that the North Korean government-affiliated hacker group Kimsuky is building AI (artificial intelligence) infrastructure that operates in local environments.
This move indicates a new phase where AI is deeply integrated into the attack activities, going beyond merely generating phishing email texts.
According to the announcement, Kimsuky has been utilizing tools such as "Ollama," "GPT4All," and "Msty" to establish a local large language model (LLM) environment that does not rely on external cloud services. Furthermore, the introduction of a document search technology known as "RAG (Retrieval-Augmented Generation)" has also been confirmed.
By operating AI in a local environment, it is possible to safely process confidential data and internal documents stolen from the intrusion site without sending them to external services. This minimizes the risk of information leakage on the attackers' side while allowing for advanced data analysis and refinement of phishing texts.
Files related to AI-assisted coding tools like "Cursor" and voice-to-text tools such as "Whisper," as well as various AI agent frameworks, have been detected from the group's infrastructure.
These are believed to have been collected to support not only the efficient automated analysis of stolen voice data and large amounts of materials but also the development of malware and the automation of the entire cyber attack process. In fact, several AI-generated documents have been discovered that are intricately disguised as legitimate financial and cryptocurrency documents.
The activities targeting cryptocurrency by North Korean-related threat actors are extremely serious. According to reports from investigative agencies, more than half of the cryptocurrency stolen in the first half of 2026, approximately $609 million (about 96.95 billion yen), is attributed to North Korean hackers. This includes large-scale breaches by TraderTraitor and organized fundraising activities using fake IT technician IDs.
Targeted attacks utilizing AI are becoming more sophisticated and difficult to detect. Cryptocurrency-related companies are required to implement comprehensive security measures such as strengthening access control, multi-factor authentication, and behavior-based monitoring (behavior detection), rather than relying on traditional detection methods that depend on unnatural text.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.




























Arthur Hayes, co-founder of BitMEX and chief investment officer at Maelstrom, has published a new essay arguing that the decade-long era of yen weakness is approaching a turning point and that the specific mechanism he expects to be used to reverse it carries direct implications for Bitcoin and gold.

