North Korean-Linked Kimsuky Uses AI Coding Agent to Build Hacking Lures
Translated from Korean and summarized by DistantNews. Read the original for the full story.
At a glance
- The Genians Security Center found the open-source AI coding agent Opencode in the creation metadata of some lure PDFs linked to Kimsuky.
- The documents imitated insurance payment notices and policy-finance guides, while malicious shortcuts used PowerShell and contacted attacker-controlled GitHub accounts or Pastebin for commands.
- South Korea selected a Naver Cloud-led consortium to develop a cybersecurity-focused AI foundation model using 256 Nvidia B200 GPUs over 10 months.
North Korea-linked hacking group Kimsuky has apparently brought an AI coding agent into its attack workflow, according to an analysis of malicious files by the Genians Security Center. Researchers said it was the first time they had found evidence of a specific AI coding agent inside actual attack files.
The center analyzed 13 Kimsuky-related malicious files collected last month and found the open-source tool Opencode in the creation metadata of some lure PDFs. Opencode can write code or create files in response to natural-language instructions. The lures were designed to resemble ordinary workplace documents, including insurance payment notices and policy-finance support guides.
The documents were not consistently convincing. One insurance notice still contained the placeholder โPayment cycle: monthly payment date (temporary value),โ while a policy-finance guide listed โup to 100 million won per company, fixed annual interest rate of 2.0% (temporary value).โ Researchers found such placeholders up to nine times in some files. Of 29 lure documents obtained by Genians, only 11 had different content. The other 18 reused the same document with different file names. Four PDFs made with Opencode had identical creation times down to the second, leading Genians to suspect they had been generated in a single automated process.
The attack began when a user opened an LNK shortcut disguised as a document inside a compressed file. PowerShell then ran, and the infected computer connected to an attacker-created GitHub account for further commands. Some variants also used Pastebin, providing another route if GitHub access was blocked. Certain files checked for security-analysis tools or virtualization software and stopped if they found one. They also created scheduled tasks with names resembling legitimate programs such as BitLocker, MATLAB and .NET. As AI reduces the time and effort needed to prepare lures, concerns are growing that attackers could launch more campaigns while retaining established evasion techniques.
The South Korean government is responding with its own AI effort. The Ministry of Science and ICT selected a Naver Cloud-led consortium on the 3rd to develop a cybersecurity-specific AI foundation model. The consortium includes LG CNS, LG AI Research, S2W, S2W, SANDS Lab, East Security, the Financial Security Institute, Seoul National University, KAIST and other organizations, with 32 institutions involved overall. It is due to receive 256 Nvidia B200 GPUs for 10 months from this month.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.