North Korea-linked hacking group Kimsuky is building local artificial intelligence environments that could help its operators develop malware, analyze stolen data and automate parts of attacks against cryptocurrency and financial targets, according to research published Monday by South Korean cybersecurity company Genians.
Genians said it identified three local large language model setups associated with the group, built with Ollama, GPT4All and Msty. The tools can run models on an operator’s own machine rather than through public cloud services, reducing the risk that sensitive prompts, files or attack plans are exposed to an outside AI provider.
The findings add a technical layer to a long-running North Korean campaign against digital-asset companies. Chainalysis estimated that North Korean hackers stole $2.02 billion in cryptocurrency during 2025, a total dominated by the $1.5 billion theft from Bybit. The blockchain analytics firm said the annual figure was 51% higher than the amount it attributed to North Korean-linked groups in the previous year.
Local AI systems could support covert attack work
Genians said Kimsuky’s AI configurations supported retrieval-augmented generation, or RAG, a technique that allows a model to answer questions using a designated collection of local documents. In an intrusion, that could allow an operator to search and summarize internal files, source code, credentials or technical documentation without uploading the material to a commercial chatbot.
The cybersecurity company also found libraries and frameworks intended to integrate language models into custom applications. Such components could be used to build specialized internal tools instead of relying on a single public AI interface.
The group’s activity included Cursor, an AI-assisted coding application, and speech-to-text tools, Genians said. Its researchers linked the collection of software to potential uses in malware development, data processing and attack automation. The report does not suggest that AI eliminates the need for experienced operators, but it could shorten routine work such as drafting scripts, interpreting logs or tailoring files for particular targets.
Kimsuky has historically been associated with espionage operations, particularly against South Korean government, academic and policy organizations. Genians’ findings indicate that the group’s AI experimentation also reaches sectors handling financial data and digital assets, where a successful compromise can provide both intelligence and direct access to funds.
Phishing documents mimic crypto and fintech businesses
Genians said Kimsuky continued to use generative AI to produce phishing documents themed around digital assets, investment strategies and fintech services. The company found files that closely resembled materials from a Korean AI-powered investment platform, using polished language, consistent formatting and visual elements associated with AI-generated marketing content.
Phishing remains one of the most practical routes into cryptocurrency businesses because it targets employees rather than attempting to defeat a platform’s security systems directly. A document framed as a market analysis, partnership proposal, recruitment exercise or investment presentation can be enough to persuade a recipient to open a malicious attachment or follow a fraudulent login link.
AI tools can make these lures more convincing by removing obvious grammatical errors, adapting wording to a target’s role and generating variations at speed. That does not make every polished document malicious, but it makes surface-level signs of fraud less reliable than they were when many campaigns depended on poorly written templates.
Chainalysis described North Korean-linked operations as using a mix of basic phishing, social engineering and infiltration through remote IT employment. The latter tactic involves operatives seeking legitimate work at technology or crypto-related firms, then gaining access to internal systems and sensitive data while appearing to be ordinary staff members.
The combination of fraudulent recruitment and AI-assisted content creates a difficult problem for companies that regularly hire remote engineers, contractors and security personnel. A convincing candidate can be used to map internal systems over time, while a separate phishing campaign may be used to obtain credentials or deliver malware.
Bybit theft shows the scale of operational risk
The $1.5 billion Bybit hack accounted for roughly three-quarters of the $2.02 billion that Chainalysis attributed to North Korean hackers in 2025. The scale of that single incident illustrates why attackers pursue large custodians, exchanges and infrastructure providers: compromising a high-value signing process or internal workflow can yield far more than attacks against individual wallet holders.
For crypto firms, the Genians report places additional pressure on basic operational safeguards rather than just perimeter defenses. Employees who handle wallet permissions, treasury operations, software releases and vendor relationships are likely to receive highly tailored messages that appear relevant to their work.
Security teams can reduce exposure by independently verifying unexpected recruiter outreach, partnership materials, software tests and requests involving wallet access or transaction approval. Files and links sent through informal channels deserve particular scrutiny when they ask a recipient to install software, enter credentials or connect a wallet.
The report also reinforces the case for separating responsibilities around large pools of assets. Multisignature custody requires approval from multiple cryptographic keys before funds can move, limiting the damage if a single employee device or credential is compromised. The model cannot prevent every attack, especially where several signers or operational systems are breached, but it gives organizations more opportunities to detect and stop an unauthorized withdrawal.
Hardware-wallet claims require careful response
A separate reported case involving an estimated $100 million exploit of Coldcard Bitcoin hardware wallets raised concerns that AI may have helped identify an obscure technical weakness. Research coverage of the incident said attackers were suspected of exploiting a vulnerability affecting wallet security.
Hardware-wallet users facing a credible compromise should avoid assuming that a standard software update alone resolves the risk, particularly if a wallet’s seed phrase may have been exposed. A seed phrase is the master recovery credential for a wallet; anyone who obtains it can generally restore the wallet elsewhere and move its assets.
Generating a new wallet on trusted equipment and transferring funds to addresses controlled by new keys can remove exposure tied to an old seed. Users should also treat unsolicited technical support offers, wallet recovery instructions and alleged security alerts with caution, since those messages are commonly used to extract recovery phrases.
Kimsuky’s apparent move toward offline AI tools does not change the underlying defenses that protect crypto organizations and users. It raises the quality and speed of social engineering, code preparation and internal reconnaissance, making disciplined approval processes, independent verification and careful key management more valuable than ever.
Strengthen your defenses against AI‑driven crypto threats with our guide on crypto safety standards and protect your assets.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

