TECH NEWS – North Korea’s Kimsuky group is preparing future attacks with locally hosted language models, RAG systems, and AI development tools. Researchers at South Korean security company Genians say the state-backed operators have moved beyond isolated experiments and are adapting AI for malware creation, data analysis, and more advanced intrusion techniques.
Investigators found Ollama, GPT4All, and Msty environments running on infrastructure controlled by the attackers. The group also experimented with Cursor and tested retrieval-augmented generation, or RAG, for searching local documents. Keeping the models on-premises prevents sensitive conversations and stolen material from being sent to outside cloud services, where the operation could be exposed or disrupted.
Kimsuky is a cyber-espionage unit associated with North Korea’s Reconnaissance General Bureau. It has spent years targeting government bodies, think tanks, universities, and security researchers through phishing messages and deceptive documents.
AI creates stronger lures and accelerates analysis
The latest campaigns commonly deliver ZIP archives containing malicious LNK files disguised as international-event material, research papers, or meeting invitations. Opening the shortcut launches an embedded PowerShell loader.
In some attacks, AI helped produce finance- and virtual-asset-themed decoys. Natural language, polished structure, and formatting that resembles genuine business documents make the lure more persuasive, while Base64 encoding, split strings, and custom decoding routines conceal the malicious behavior.
The PowerShell script harvests extensive system details, including operating-system version and architecture, configuration, PC type, installation and boot history, and the list of running processes. Those details allow the operators to assess the compromised machine and plan follow-up activity.
Git-based control, RAG, and speech recognition
As in previous Kimsuky operations, public Git repositories served as command-and-control infrastructure. Genians identified multiple GitHub repositories managed by the actor, some of which stored configuration files, PowerShell scripts, and payloads used later in the infection chain.
The months-long investigation indicates that the same infrastructure supported malware development and testing, stolen-data management, and AI research. The spies collected libraries such as LLaMaSharp and Microsoft.Extensions.AI along with OpenAI and Azure.AI.OpenAI packages, suggesting an effort to connect local model execution, document retrieval, automated agents, and commercial AI services.
Logs also pointed to Whisper speech-recognition models, code editing with Cursor, and RAG experiments for document-based question answering. RAG could be especially valuable to an attacker because it can rapidly and partly automatically identify useful information across a large cache of stolen files.
Defenders need to prioritize behavior
The researchers found no evidence that Kimsuky is training its own models; the group currently appears focused on applying existing technology to malware and attack operations. That still weakens content-based detection, because odd phrasing, mistranslation, spelling mistakes, and poor formatting are no longer reliable clues when AI can generate convincing decoys.
Organizations should therefore watch not only known indicators of compromise but also unusual activity after an LNK file runs: PowerShell execution, persistence mechanisms, and outbound communications. Those behaviors can expose an intrusion even when the bait document itself looks flawless.
Source: The Register
![A Modder Has Turned GeForce Now into a High-End Cloud PC! [VIDEO]](https://thegeek.games/wp-content/uploads/2026/08/theGeek-GeForce-Now-cloud-PC-300x365.jpg)



Leave a Reply