North Korean state-sponsored hackers are using artificial intelligence tools to automate cyberattack tasks such as spear-phishing and document generation [1], [2].

This development marks a shift in how state-sponsored actors utilize AI. By running these tools locally, hackers can scale their operations while avoiding the digital footprints left when using external AI services.

South Korean cybersecurity firm Genians said the hacking group, known as Kimsuky, developed these tools to process documents without transmitting sensitive data to outside providers [1], [2]. This approach reduces the risk of detection by security firms that monitor traffic to known AI platforms [3].

Kimsuky has historically focused on espionage and data theft. The integration of AI allows the group to automate the creation of convincing phishing emails and documents, tactics used to trick targets into revealing credentials or installing malware [3], [4].

Local deployment ensures that the AI models remain under the group's direct control. This prevents external companies from flagging malicious prompts or blocking the accounts used to generate attack materials [5].

Security analysts said the ability to automate these tasks increases the volume of attacks the group can launch simultaneously [3]. The use of local AI removes the dependency on internet connectivity for the generation phase of an attack—a strategic advantage for operatives working in restricted environments [1], [2].

Hackers can scale their operations while avoiding the digital footprints left when using external AI services.

The move toward localized AI models indicates a maturing threat landscape where adversaries are bypassing the safety filters and monitoring systems of commercial AI providers. By internalizing these capabilities, state-sponsored groups like Kimsuky can produce high-quality social engineering content at scale without alerting global cybersecurity monitors, making spear-phishing attacks harder to distinguish from legitimate communications.