{"id":23929,"date":"2026-08-11T05:20:03","date_gmt":"2026-08-11T05:20:03","guid":{"rendered":"https:\/\/futureknowledge.in\/?p=23929"},"modified":"2026-08-11T05:20:03","modified_gmt":"2026-08-11T05:20:03","slug":"north-korean-spies-are-running-local-llms-to-cause-ai-mischief","status":"publish","type":"post","link":"https:\/\/futureknowledge.in\/?p=23929","title":{"rendered":"North Korean spies are running local LLMs to cause AI mischief"},"content":{"rendered":"<p>Kimsuky&#039;s phishing attacks get an AI boost<\/p>\n<p>North Korean government snoops are operating LLMs locally and collecting technology to weave AI into their attack operations, according to South Korean security firm Genians.<\/p>\n<p>The researchers said they observed Kimsuky setting up and operating local LLM environments using Ollama, GPT4All, and Msty, experimenting with other AI tools such as Cursor, and using retrieval-augmented generation (RAG) for local document searches. This prevents the data from getting sucked into the cloud where enemies might see it and try to stop it.<\/p>\n<p>Kimsuky, a cyber-espionage crew that operates under North Korea&#039;s Reconnaissance General Bureau, has for years used phishing and decoy documents in attacks targeting government agencies, think tanks, academia and security research organizations.\u00a0<\/p>\n<p>Genians\u2019 findings \u201cprovide concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques,\u201d the researchers said in a Monday report.<\/p>\n<p>The North Korean group\u2019s recent phishing emails use ZIP archives containing malicious LNK files &#8211; Kimsuky typically disguises these as materials related to international events, research reports, or meeting requests. When the recipient opens the archive and executes the LNK file contained within it, the shortcut runs an embedded PowerShell loader.<\/p>\n<p>In some cases, the goon squad used AI to create lures related to virtual assets and finance, we\u2019re told. These decoy documents \u201cuse natural language, a highly polished structure, and formats similar to actual business materials to increase user trust and induce the execution of malicious files,\u201d the security analysts noted.<\/p>\n<p>Additionally, the Pyongyang spies use various obfuscation techniques, including Base64 encoding, string splitting, and custom decoding routines, to hide the files\u2019 malicious behavior.<\/p>\n<p>The PowerShell script collects a ton of system information, including operating system version and architecture, system configuration, PC type, operating system installation and boot history, and a list of running processes. The attackers use this information to assess the infected environment and support follow-on attacks.<\/p>\n<p>As with earlier Kimsuky campaigns, these intrusions use Git repositories for command-and-control (C2) infrastructure.<\/p>\n<p>\u201cDuring the analysis, Genians Security Center identified multiple public GitHub repositories operated by the threat actor,\u201d the researchers wrote. \u201cOne repository contained not only configuration files and PowerShell scripts, but also various payloads used in subsequent attacks.\u201d<\/p>\n<p>Additionally, the months-long investigation uncovered the spies also using the Git-based C2 infrastructure for malware development and testing, stolen data management, and AI technology research.<\/p>\n<p>This included setting up multiple local LLM environments using Ollama, GPT4All, and Msty on infrastructure it controlled. \u201cBecause the local approach prevents conversation data from being transmitted to external AI services, it reduces the risk of external exposure, making it a particularly attractive option for a state-sponsored threat actor,\u201d Genians said.<\/p>\n<p>The miscreants also collected a \u201clarge number\u201d of libraries, such as LLaMaSharp and Microsoft.Extensions.AI, plus packages including OpenAI and Azure.AI.OpenAI, which call and integrate commercial AI services into their own custom applications.<\/p>\n<p>\u201cThe fact that development components spanning &#039;local AI execution \u2192 document retrieval (RAG) \u2192 automated agents \u2192 external AI integration&#039; were collected together strongly suggests that they were not gathered out of simple curiosity, but for the direct development of an AI-based tool designed for a specific purpose,\u201d according to the threat hunters.<\/p>\n<p><em>Source: <a href='https:\/\/www.theregister.com\/security\/2026\/08\/10\/north-korean-spies-are-running-local-llms-to-cause-ai-mischief\/5285632' target='_blank'>Read the original article on www.theregister.com<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kimsuky&#039;s phishing attacks get an AI boost North Korean government snoops are operating LLMs locally and collecting technology to weave AI into their attack operations, according to South Korean security firm Genians. The researchers said they observed Kimsuky setting up and operating local LLM environments using Ollama, GPT4All, and Msty, experimenting with other AI tools [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":23930,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36,3],"tags":[25,29,33],"class_list":["post-23929","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-share-suggestions","category-technology","tag-impact-msft","tag-signal-avoid","tag-stage-stage-4"],"_links":{"self":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/23929","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23929"}],"version-history":[{"count":0,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/posts\/23929\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=\/wp\/v2\/media\/23930"}],"wp:attachment":[{"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23929"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23929"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/futureknowledge.in\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23929"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}