Exclusive news, data and analytics for financial market professionalsLearn more aboutRefinitiv

Miniatures of people with computers are seen in front of North Korea flag in this illustration taken July 19, 2023. REUTERS/Dado Ruvic/Illustration/File Photo Purchase Licensing Rights, opens new tab
-
Companies
Follow
SEOUL, Aug 10 (Reuters) - A North Korean hacking group built large language model tools and collected software that could help automate cyberattacks, analyse stolen material and produce more convincing phishing campaigns, a South Korean cybersecurity firm said on Monday.
The cybersecurity firm, Genians (263860.KQ), opens new tab, said it found evidence that the North Korean-linked group Kimsuky had set up tools for running and managing AI models locally, including Ollama, GPT4All and Msty, alongside document search technology known as retrieval augmented generation (RAG).
Jumpstart your morning with the latest legal news delivered straight to your inbox from The Daily Docket newsletter. Sign up here.
Advertisement · Scroll to continue
According to the company, the tools could allow operators to process documents without sending sensitive information to outside AI services.
Genians also found AI agent development frameworks, speech-to-text software and Cursor, an AI-assisted coding tool, on infrastructure it linked to the campaign.
The findings suggest Kimsuky is moving beyond using generative AI to create phishing lures and is building capacity to integrate existing AI models into malware development, data analysis and attack automation, Genians said in a report.
Genians also said it found finance and cryptocurrency-themed decoy documents that appeared to have been generated with AI. The materials were designed to resemble legitimate investment reports and other workplace documents, it said.
Advertisement · Scroll to continue
The company's findings could not be independently verified.
North Korea has for years used state-linked cyber units for espionage, financial theft and revenue generation, according to U.S. and South Korean authorities, as well as cybersecurity experts.
The U.S. Treasury in 2023 sanctioned Kimsuky, opens new tab as a North Korean government-controlled cyber-espionage group, saying it gathered intelligence in support of Pyongyang's strategic objectives.
Reporting by Joyce Lee Editing by Ed Davies
Our Standards: The Thomson Reuters Trust Principles., opens new tab
-
X
-
Facebook
-
Linkedin
-
Email
-
Link
Read Next / Editor's Picks
- August 8, 2026Legalcategory
OpenAI flags possible critical cybersecurity risk in upcoming model
- August 7, 2026Legalcategory
Levi Strauss reveals cybersecurity breach amid wider wave of attacks
- August 7, 2026Businesscategory
Who is liable when AI goes rogue? Lawyers see new risks
- August 7, 2026Legalcategory
Chinese startup Moonshot's AI model breaks out of testing environment, researchers say
- August 6, 2026Technologycategory
Akamai beats quarterly estimates on cloud infrastructure demand
- August 6, 2026Technologycategory
Gen Digital raises annual forecast on strong cybersecurity demand
- August 6, 2026Sportscategory
French rugby club Stade Francais reports cyberattack
- August 6, 2026
China's Zbtlink suspends sales of routers found to contain backdoor
- August 7, 2026Worldcategory
EXCLUSIVE
Hackers targeted US private equity, other firms including Blackstone, CME
- August 6, 2026Worldcategory
- August 6, 2026Legalcategory
China launches cybersecurity review into Palo Alto Networks products
- 11 hours agoLegalcategory
Trump’s tech ties come under bipartisan fire after AI agents go rogue
- August 5, 2026Technologycategory
Meta AI model hacks another company during testing
- August 5, 2026Legalcategory
Major Wall Street firms targeted in attempted cyberattacks, sources say
- August 6, 2026Worldcategory
Russia steps up disinformation before German elections, security sources say
Read Original at Reuters →













