Kimsuky has been setting up local AI environments as it looks for ways to bring artificial intelligence into its cyberattack operations. The North Korea-linked threat actor, which has frequently targeted the cryptocurrency and financial sectors, was found to have established local LLM environments using Ollama, GPT4All, and Msty.
Genians said the local approach prevents conversation data from being transmitted to external AI services, thereby reducing the risk of external exposure.
AI Added to Crypto Attack Playbook
According to the report, the activity showed the group was building capabilities to integrate artificial intelligence into its attacks. In GPT4All, investigators detected a database linked to its LocalDocs feature. The cybersecurity firm said the evidence indicates that the threat actor may have attempted to connect documents in its possession to an AI system and use them as a knowledge source.
The group also collected libraries and frameworks that can integrate artificial intelligence into software. These included LLaMaSharp, Microsoft Semantic Kernel and Microsoft Agents AI. The components covered local AI execution, document retrieval, automated agents and integration with external AI services.
The investigation also found files related to Whisper and faster-whisper, speech-to-text tools. Genians said such tools could be abused to process and analyze material stolen or collected from compromised systems.
The company further added,
“This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques.”
North Korea, Hackers and the Crypto Industry
Zooming out, North Korea-linked attackers were responsible for more than half of the cryptocurrency stolen in the first half of 2026, according to Blockaid’s recent findings. The firm said DPRK-linked attackers stole about $609 million during the period, making up roughly 55% of the $1.1 billion lost across 212 incidents.
The KelpDAO and Drift Protocol attacks were linked to TraderTraitor, a North Korean state-sponsored group associated with Lazarus. The two attacks accounted for most of the DPRK-linked losses. Humanity Protocol also lost $32 million in an attack tied to the same group. The findings highlight North Korea’s continued role in some of the biggest crypto thefts of 2026.
These operatives have also sought access from inside the industry. Prominent blockchain investigator ZachXBT had previously reported that North Korean IT workers generated more than $3.5 million in crypto through fake developer identities and a coordinated payment system. The operation came to light after a hacker compromised one worker’s device and exposed records tied to nearly 390 accounts.
The leaked data showed that the operation was bringing in about $1 million a month. Workers used fake identities and forged documents to secure jobs on different projects. Their payments were tracked through an internal platform, where workers reported their income and administrators managed transfers. Records from the compromised device also showed the use of VPNs and multiple fabricated personas. Chat logs revealed that dozens of workers were active in the same system.
The post North Korea’s Kimsuky Turns to AI as Crypto Firms Face New Threats appeared first on CryptoPotato.