North Korean Group Develops AI Tools to Automate Cyberattacks, Report Says
Translated from Spanish, summarized and contextualized by DistantNews.
At a glance
- A North Korean cybercrime group, Kimsuky, has developed AI tools to automate cyberattacks, according to South Korean cybersecurity firm Genians.
- These tools enable operators to process documents and create phishing lures without sending sensitive data to external AI services.
- The development signifies a consistent progression in the group's capabilities, despite a lack of identified independent model training.
A North Korean cybercrime group, identified as Kimsuky, has reportedly developed artificial intelligence tools to automate its cyberattacks, a South Korean cybersecurity firm announced. Genians, a specialist in cyber defense, observed indications that the group, linked to North Korea and sanctioned by the U.S., has configured a local language model and an environment for using generative AI throughout its attack processes.
These newly developed tools are designed to allow Kimsuky operators to process documents and generate content without transmitting confidential information to external AI services. Genians also reported finding voice-to-text software and an AI-assisted coding tool within the group's arsenal. The firm noted that Kimsuky is expanding its use of AI by creating sophisticated cyber scam lures, including fake documents designed to mimic legitimate financial and cryptocurrency reports.
Genians emphasized that the significant aspect of this advancement is not merely the creation of AI-generated documents, but the "consistent" development of capabilities by the group. This progress has been observed even though no evidence of independent model training by Kimsuky has been identified to date. U.S. authorities have previously warned that Kimsuky, which they place under Pyongyang's military intelligence organization, employs hacking tactics targeting research centers, academic institutions, non-profits, and media outlets.
This development aligns with broader trends observed in cyber warfare. In May, Google's Threat Intelligence Group alerted that actors linked to North Korea, China, and Russia were intensifying their use of AI. These actors are reportedly leveraging AI to discover vulnerabilities, create more sophisticated malware, and execute disinformation campaigns, signaling an "industrialization" of offensive AI technology.
The change that stands out about this development is not the evidence of AI document creation, but a consistent process of capability development.
Originally published by ABC Color in Spanish. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.