
Kimsuky integrates AI into cyberattacks on crypto and finance
South Korean cybersecurity firm Genians Security Center reported that the North Korea-linked hacking group Kimsuky (also tracked as APT43, Thallium, Black Banshee, Velvet Chollima) has begun embedding generative AI into its attack infrastructure. According to the report, the group is using AI to create fake decoy documents themed around crypto assets, investment strategies, and fintech services, as well as to analyze stolen data.
On servers linked to Kimsuky, researchers found several tools for running local AI models: Ollama, GPT4All with its retrieval-augmented generation feature LocalDocs, the Msty app, the LLaMaSharp library, and the Microsoft.SemanticKernel and Microsoft.Agents.AI frameworks. Using local rather than cloud-based models lets the group process documents without sending sensitive data to outside AI services. One of the decoy files found was literally named "Marketing-Service-Agreement-Pumpfun-AI-Attack-Defence.docx" — a direct reference to the meme-coin launchpad Pump.fun, confirming the crypto angle of the campaign.
The attack chain centers on phishing emails carrying ZIP archives that hide malicious LNK files disguised as business documents. Opening them triggers a PowerShell script that pulls an encrypted payload via the GitHub Raw Content API — the AsyncRAT remote-access trojan, disguised as ordinary PNG images. Several indirect clues point back to North Korea: a Dubeolsik keyboard layout with distinctive North Korean spelling patterns, use of Astrill VPN, a Chinese-language version of WPS Office, and hardcoded GitHub access tokens. Reuters, which first reported on the findings, noted separately that Genians' conclusions could not be independently verified.
- Tools found on Kimsuky servers: Ollama, GPT4All (LocalDocs), Msty, LLaMaSharp, Microsoft Semantic Kernel
- Payload is the AsyncRAT trojan disguised as PNG files, delivered via GitHub
- Targets: the crypto asset sector, South Korean fintech, diplomatic missions, military and government bodies
This isn't the first time North Korea-linked groups have made headlines in crypto: we previously covered how Lazarus Group was behind 76% of all DeFi hack losses in the first half of 2026, and how a separate group targeted Wall Street's biggest firms via fake IT-helpdesk phone calls — social engineering, and now AI tooling, keep becoming sharper weapons against the financial sector.
Nothing here should be taken as financial advice — just information to consider.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7

Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
227AI




