
North Korean hacking group Kimsuky has established and tested local artificial intelligence tools as it researches ways to integrate AI technology into malware development and attack techniques, according to new cybersecurity research from Genians. The group has built three local AI environments using Ollama, GPT4All and Msty, giving them access to AI tools that can run without relying on external cloud services. This development comes as North Korean hackers have stolen an estimated $2.02 billion in cryptocurrency during 2025, with most losses attributed to the February 2025 attack against Bybit where over 400,000 Ether worth about $1.5 billion was stolen. The FBI has attributed the breach to North Korea and identified the actors responsible under its TraderTraitor designation.
According to Genians, Kimsuky has expanded its AI toolkit beyond the initial three local environments to include RAG technology for rapid data extraction from stolen files and speech-to-text software for analyzing stolen audio. The group also employs Cursor, an AI coding tool that accelerates malware development and generative AI for creating more realistic phishing documents and messages. As reported by Reuters, these AI-agent frameworks enable the group to examine stolen documents without transferring private information to outside AI services, reducing operational risks while maintaining sophisticated attack capabilities. The group reportedly used financial and cryptocurrency decoy documents that appeared to be AI-generated, mimicking investment reports as part of their crypto-focused attacks.
Cybersecurity firm Kumio has revealed that North Korean hackers compromised 1,640 companies across 57 countries, marking one of the most extensive cybersecurity breaches in recent history. According to Kumio's CTO Vangelis Stykas, the hackers used fake job interviews as lures to achieve root access to crucial systems in numerous organizations. The breaches were maintained for 22 months through command-and-control servers, with 700 to 800 organizations suffering severe cybersecurity intrusions. This incident underscores serious vulnerabilities in cybersecurity protocols and raises alarms for the cryptocurrency sector, as many firms were specifically targeted for crypto theft.
Security researchers have confirmed the core attack chain through independent analysis. As reported by JUMPSEC, the company obtained source code from an active BlueNoroff phishing kit after exposed JavaScript source maps, finding a victim-acquisition platform that abuses compromised Telegram contacts, profiles cryptocurrency wallets and delivers malware to selected targets on Windows and macOS systems. The attack uses fake meetings that ask for webcam access before operators join with prerecorded video, then display supposed audio problems and fake software updates. The displayed troubleshooting text contains deceptive ClickFix commands that place attacker-controlled commands onto the clipboard when copied.
The revelations about North Korean hackers' extensive cybersecurity breaches and AI-assisted attack capabilities have created significant uncertainty in the cryptocurrency market. The crypto market just witnessed a sharp move as these revelations emerged, with the lack of significant price movement reflecting trader caution. With no substantial trading volume reported in the last 24 hours, traders remain cautious amidst these revelations, highlighting the need for enhanced security measures in the cryptocurrency space. The focus on lax security measures raises concerns about potential vulnerabilities in other platforms, possibly leading to further scrutiny from regulators, while stakeholders should monitor for any shifts in trading volume as firms reassess their cybersecurity protocols.