The North Korean hacking group Kimsuky has built large-language-model AI tools to automate cyberattacks and analyze stolen material [1, 2].

This development marks a shift in state-sponsored cyber warfare, as AI allows attackers to scale operations and bypass traditional security filters with higher precision.

A South Korean cybersecurity firm identified the tools in a report released Monday [1, 2]. The group is using these AI capabilities to generate more persuasive spear-phishing campaigns, which are targeted emails designed to trick specific individuals into revealing sensitive information [1, 2, 3].

Beyond phishing, the AI tools are designed to automate the execution of cyberattacks and process large volumes of stolen data [1, 2, 3]. This allows the group to identify valuable information within stolen datasets more quickly than human analysts could.

"The group is using AI‑generated documents in spear‑phishing attacks," said a spokesperson for the South Korean cybersecurity firm [1].

The use of large-language models helps the group craft documents that mimic the tone and style of legitimate organizations, making the deception harder to detect [1, 2]. By automating the analysis of stolen material, Kimsuky can refine its targeting for future operations in real time [1, 2].

Security experts note that the integration of AI into the hacking pipeline reduces the manual labor required for each phase of an attack, from initial reconnaissance to final data exploitation [1, 2].

The group is using AI‑generated documents in spear‑phishing attacks

The adoption of LLMs by Kimsuky suggests that state-sponsored actors are moving beyond generic malware toward highly personalized, automated social engineering. This increases the risk to government officials and defense contractors, as AI-generated phishing is significantly more difficult for humans to distinguish from legitimate communication than previous templates.