According to Genians, a South Korean cybersecurity outfit, these North Korea-linked operators are using such AI to make sense of what they have taken and to produce content that is all too believable, thus complicating matters for any defence against phishing. The firm says Kimsuky is putting in the work to build its own AI capacity to automate the process and raise the bar.
What investigators say they found
Genians has put forward evidence of Kimsuky installing software to host and control large language models. Their setup makes use of Ollama, GPT4All and Msty, and retrieval augmented generation (RAG) to get to grips with large document sets.
On top of that, researchers have tied the infrastructure to Cursor for coding as well as speech-to-text and AI agent frameworks. Hosting the models on their own systems means the operators do not have to turn to external AI services to handle sensitive files.
Why local, ChatGPT-like models change the game
There is an advantage to running things in private: it allows for the swift sifting of documents at scale and the creation of messages with genuine context. Genians sees this as a departure from the sort of emails AI might write by default; instead, existing models are being woven into malware and attack automation.
Such a workflow shortens the window between the theft and its exploitation. It also lends a specificity to the phishing that ties in with a victim’s organisation or role, stripping away the kind of telltale signs users would normally trust to identify a scam.
Fake reports that look like real work
The report from Genians notes some finance and cryptocurrency decoys that bear the hallmarks of AI authorship. They are made to pass for the sort of everyday workplace material or investment report one would expect to see.
It is enough to persuade a target to open a booby-trapped file or put faith in a fraudulent scheme. When even a spreadsheet or a glossy offer can be synthetic, the old way of visually vetting an email is of little use.
Key developments highlighted by Genians
The company points to these as the most significant aspects of the campaign:
– Local deployment of Ollama, GPT4All and Msty by Kimsuky
– RAG for the interpretation of large document sets
– Systems running AI agents, Cursor and speech-to-text
– Building capacity for automation, analysis and malware
– Decoys in the crypto and finance space produced by AI
A broader playbook, familiar goals
Genians’ account is in step with the way cybercriminals are employing AI throughout an operation, not merely to put together an email. One sees it in the social engineering of North Korean hackers who will present themselves as job applicants to an IT firm, combining technical tools with human ruse.
While the company’s findings have not been independently verified, authorities and experts have said in past assessments that the pattern is consistent with the group’s modus operandi.
Who Kimsuky is and why it matters now
U.S. and South Korean officials, along with those in the know, have long pointed to state-sponsored units in North Korea as the source of espionage and financial theft. In 2023 the U.S. Treasury went so far as to sanction Kimsuky as a government-controlled cyber-espionage entity.
Should Kimsuky be able to string AI systems together behind closed doors, the volume and quality of their lures will likely improve. Using RAG to mine inboxes and then weaponising the results with automated tooling makes for a scam that is disconcertingly authentic.
What users should keep in mind
A professional appearance is no guarantee of safety when it comes to AI. An internal memo or an investment deck can be machine-made and every bit as malicious.
Genians would have it as a warning that the playing field is changing. We may be seeing the next wave of phishing where the message seems to know you because, effectively, the model does.











