The North Korean hacking group Kimsuky has developed artificial-intelligence tools to automate cyberattacks and analyze stolen documents [1, 2].

This development marks a shift in state-sponsored cyber warfare by allowing attackers to scale malicious operations while avoiding the digital footprints left by third-party AI services.

According to reports released Monday, the group built an offline large-language-model lab on its own attack servers [3, 5]. The infrastructure was discovered by Genians, a South Korean cybersecurity firm [1, 5]. By hosting these tools locally, Kimsuky can process stolen information and generate phishing content without sending sensitive data to external AI providers [1, 4].

These AI tools are designed to streamline the creation of more convincing phishing messages [2, 4]. Phishing is a primary method used by the group to gain unauthorized access to secure networks and steal intelligence.

Beyond message generation, the offline AI environment allows the group to analyze large volumes of stolen files more efficiently [5]. This capability reduces the time required to find actionable intelligence within massive datasets, a process that previously required significant manual effort.

The move toward localized AI labs suggests a strategy to evade detection by security firms that monitor traffic to popular AI platforms [1, 3]. By isolating the AI environment, Kimsuky minimizes the risk of exposure while increasing the speed and volume of its attacks [1, 3].

The reports were published on Aug. 10 [1].

The group developed an AI environment to automate cyberattacks and analyze stolen data.

The adoption of offline AI by Kimsuky indicates that state-sponsored actors are overcoming the limitations of public AI safeguards. By deploying private LLMs, these groups can bypass the safety filters and monitoring tools implemented by commercial AI companies, enabling more sophisticated and stealthy social engineering campaigns at a scale previously impossible for human operators.