North Korea’s cyber capabilities have undergone a significant transformation in recent years, largely driven by the strategic application of artificial intelligence (AI). A recent report by the cybersecurity firm Genians reveals a concerning trend: Kimsuky, a hacking group linked to North Korea’s intelligence services, has increasingly utilized AI to bolster its cyberattacks against a wide range of targets, including military installations, diplomatic offices, and academic institutions. This shift represents a substantial departure from traditional methods of spear-phishing and malware creation, highlighting a novel approach to threat amplification. Since 2026, Kimsuky has employed AI to automate the generation of malicious documents, such as research reports and invitations, a process that has become remarkably efficient. The report details that Kimsuky has used open-source tools like Ollama, GPT-4All, and Msty to run large language models without an internet connection, effectively bypassing traditional security measures. Genians’ analysis indicates that the AI-driven process involves creating highly polished documents on a massive scale, drastically increasing the speed and scope of the attacks. A key aspect of this strategy is the avoidance of detection; Kimsuky has been employing techniques like creating decoy documents and obfuscating malicious code, making it difficult for security firms to identify the source of the attacks. The group’s history of targeting financial gain has also contributed to the escalating threat. North Korea has been implicated in past incidents, notably the 2014 hacking of Sony Pictures, a highly publicized incident that drew international condemnation. In 2014, US authorities identified North Korea as the perpetrator of the hacking, leading to a significant diplomatic backlash. The report underscores that North Korean hackers are far more adept at utilizing and exploiting AI tools to enhance their efforts, potentially exceeding the capabilities of previous adversaries. Recent research by Mark T. Hofmann, a criminal and intelligence analyst specializing in cybercrime, suggests that AI is fundamentally reshaping the landscape of cybercrime. Hofmann stated that AI has led to a seismic shift in cybercrime, lowering the bar for malicious actors and making it easier to carry out attacks. He predicts that AI-supported cyberattacks will become a persistent and accelerating phenomenon, posing a significant challenge to cybersecurity professionals worldwide. The development of AI-generated viruses, surpassing anything previously seen, represents a significant concern, highlighting the potential for unforeseen consequences. The US government has also been actively researching AI-powered viruses, with researchers recently announcing the creation of viruses that cannot be found in nature – a development that raises both excitement and anxiety about the potential for unforeseen consequences. The report emphasizes the need for proactive measures to mitigate the risks posed by AI-driven cyberattacks. The use of AI has led to a shift in cybercrime, which lowers the bar for bad actors to carry out malicious activity. Threat actors across the globe are now utilizing more and more generative AI and, much worse, AI agents to accelerate their cyberattacks. The dark side of AI is one of the main challenges of this decade. AI-supported cyberattacks will become a regular phenomenon.”]
Watch Related Video
Source: Al Jazeera























