Genians, Inc.Report highlights Kimsuky's use of AI, potentially increasing demand for Genians' cybersecurity solutions.

North Korean hacker group Kimsuky is using local AI systems to carry out sophisticated cyberattacks targeting cryptocurrency and financial companies, according to a report by cybersecurity firm Genians. The group has built and run three local large language model environments using Ollama, GPT4All, and Msty tools, enabling offline operation and the use of Retrieval-Augmented Generation technology. They have also been found collecting libraries and frameworks to embed language models into custom-developed software, alongside the Cursor code assistant and speech-to-text tools, with the aim of developing spamware and malware, analyzing data, and automating attacks. Genians says this is evidence that Kimsuky is moving beyond occasional AI experimentation and preparing to integrate this technology into real attack capabilities. Meanwhile, they have also been using generative AI to create convincing phishing documents related to digital assets, investment strategies, and fintech services, closely mimicking publications from Korean investment platforms. Last year, North Korean hackers stole 2.02 billion dollars worth of cryptocurrency, including the 1.5 billion dollar Bybit exchange hack, and the recent 100 million dollar Coldcard Bitcoin hardware wallet breach is suspected to have stemmed from an AI-discovered vulnerability.
Genians, Inc.Report highlights Kimsuky's use of AI, potentially increasing demand for Genians' cybersecurity solutions.
Article mentions North Korean hackers stole $1.5 billion from Bybit, indicating a security breach.
Coldcard wallet breach suspected from AI-discovered vulnerability, affecting Coinkite's reputation.