North Korea-linked hacking group Kimsuky has built three local AI environments as part of preparations for cyberattacks targeting cryptocurrency and financial companies, according to new cybersecurity research.

Genians, a South Korean cybersecurity firm, said in a report released Monday that it found evidence of Kimsuky operating local large language model environments through Ollama, GPT4All and Msty, giving the group access to AI tools that can run without relying on external cloud services.

Kimsuky has built local AI systems for cyberattacks

Running models locally allows operators to make queries without sending potentially sensitive attack information to third-party AI providers. According to the research, the environments also support retrieval-augmented generation, which can connect an AI model with additional information supplied by its operator.

Alongside the three environments, researchers found libraries and frameworks that can embed language models into custom software. Kimsuky had also collected the AI coding assistant Cursor and speech-to-text tools as it assembled its AI infrastructure.

Rather than developing new AI models, the activity examined by Genians centered on putting existing open-source technology to work across malware development, data analysis and attack automation.

The firm assessed that the activity had moved beyond isolated tests because Kimsuky was continuously preparing to incorporate AI into operational attack capabilities. However, its findings did not show that the group was developing proprietary AI models from scratch.

Keeping the models on local infrastructure could also allow the hackers to work with information without submitting it to external cloud systems, according to the report. The collection of supporting software indicates that the AI environments form part of a larger technical setup rather than functioning only as standalone chat tools.

AI-generated phishing documents target crypto firms

Kimsuky has also continued using generative AI to prepare phishing material focused on cryptocurrency, investment strategies and fintech services, according to Genians.

Researchers identified polished documents that closely copied material associated with a Korean AI-powered investment platform. The files used natural language, consistent formatting and professional design elements that the cybersecurity firm associated with AI-generated content.

Such material provides another use for the group’s AI infrastructure beyond coding and data processing. Instead of relying only on poorly written phishing emails, the operators can use generative tools to prepare documents designed around financial subjects relevant to their intended targets.

The findings add Kimsuky to a series of North Korea-linked operations using newer technical and social-engineering methods against the cryptocurrency industry.

In July, cybersecurity firm JUMPSEC reported that BlueNoroff, another North Korea-linked group, was operating fake Zoom and Microsoft Teams meetings that profiled cryptocurrency users before malware was delivered.

JUMPSEC recovered source code from an active phishing kit after its operators accidentally exposed JavaScript source maps. The code contained wallet-scanning functions, operator controls, and separate malware delivery routes for Windows and macOS.

Once a target entered a fake meeting page, the system checked for Ethereum wallet connections and non-EVM wallets, including Solana tools, before sending the results to an operator panel. Windows implants could also identify browser extensions across Chrome, Edge, Brave, Opera, Vivaldi and Firefox variants, allowing operators to check for wallets such as MetaMask.

The attackers could then decide whether to continue the intrusion based on information gathered from the target, JUMPSEC found.

North Korean hackers are combining AI with social engineering

AI also appeared inside BlueNoroff’s fake meeting operation, although in a different role from the local models identified in the Kimsuky research.

According to JUMPSEC, operators combined AI-generated headshots with body movements taken from previous meetings to create convincing participants for fake video calls. Victims could arrive through a Telegram account belonging to a real contact whose account had already been compromised, before receiving a Calendly invitation that redirected them to a fake meeting domain.

During the call, an operator could display a prepared video, send messages about a supposed microphone problem, and trigger a fake Zoom software update. On Windows, the resulting ClickFix process used PowerShell and VBScript, while the macOS route delivered a fake meeting installer alongside information-stealing malware.

Arctic Wolf had previously identified more than 80 lookalike Zoom and Teams domains associated with related operations. About 80% of the targets it identified worked in crypto, blockchain finance or connected investment sectors, while founders and chief executives represented 45% of the identified targets.

North Korean operations have also sought access from inside crypto companies rather than relying solely on phishing or malware.

In July, Consensys temporarily stopped product releases after discovering that a consultant linked to North Korea had gained access to its systems for roughly one month, according to Drop Site News.

The consultant, who operated under the name Tyler Knapp and used the GitHub handle “imyugioh,” contributed to core MetaMask platform code, including components connecting cryptocurrency users with third-party fiat payment providers.

Consensys general counsel Matt Corva said a third-party service provider had introduced the consultant to the company. The company terminated his access after identifying the threat and said its investigation found no stolen assets or data, malicious code or impact on user security.

Separate research from the Ketman Project identified about 100 suspected North Korean IT workers operating under false identities across 53 crypto and Web3 projects. Investigators also traced suspected groups across 11 code repositories where projects had already merged 62 pull requests before the activity was detected.

North Korea stole more than $2 billion in crypto in 2025

The development of AI-assisted attack infrastructure comes after North Korean hacking groups stole an estimated $2.02 billion in cryptocurrency during 2025, according to Chainalysis data previously reported by crypto.news.

Most of the year’s losses came from the February 2025 attack against Bybit, where more than 400,000 Ether and staked Ether worth about $1.5 billion were stolen. The FBI attributed the breach to North Korea and identified the actors responsible under its TraderTraitor designation.

Bybit has since taken the dispute into a U.S. federal court. On Aug. 8, the exchange sued the Democratic People’s Republic of Korea, its Reconnaissance General Bureau intelligence agency and the Lazarus Group in the U.S. District Court for the District of Columbia.

The exchange also obtained a preliminary injunction covering certain stolen assets held by unidentified defendants. The order prevents the identified assets from being transferred, sold or otherwise disposed of while the civil case proceeds, although it does not constitute a final ruling over ownership or liability.

Blockchain tracing became increasingly difficult after the Bybit theft as the attackers converted assets into Bitcoin and dispersed funds across thousands of wallets. By April 2025, Bybit CEO Ben Zhou said 27.6% of the stolen funds could no longer be tracked.

Researchers have also warned that AI could reduce the time attackers need to identify weaknesses in software. NEAR Protocol co-founder Illia Polosukhin has said AI is increasing hackers’ ability to locate vulnerabilities faster than conventional security processes can patch them.

The $100 million Coldcard Bitcoin hardware wallet exploit has also been suspected of originating from an obscure vulnerability uncovered with AI. Separately, North Korean operators continue to use phishing, fake remote workers and compromised online identities, while the latest Genians research shows Kimsuky preparing local AI models for malware development, data analysis and attack automation.