North Korea’s Kimsuky Turns to AI as Crypto Firms Face New Threats

Kimsuky has been setting up local AI environments as it looks for ways to bring artificial intelligence into its cyberattack operations. The North Korea-linked threat actor, which has frequently targeted the cryptocurrency and financial sectors, was found to have established local LLM environments using Ollama, GPT4All, and Msty.
Genians said the local approach prevents conversation data from being transmitted to external AI services, thereby reducing the risk of external exposure.
AI Added to Crypto Attack Playbook
According to the report, the activity showed the group was building capabilities to integrate artificial intelligence into its attacks. In GPT4All, investigators detected a database linked to its LocalDocs feature. The cybersecurity firm said the evidence indicates that the threat actor may have attempted to connect documents in its possession to an AI system and use them as a knowledge source.
The group also collected libraries and frameworks that can integrate artificial intelligence into software. These included LLaMaSharp, Microsoft Semantic Kernel and Microsoft Agents AI. The components covered local AI execution, document retrieval, automated agents and integration with external AI services.
… Continue reading the full article at the original source below.



