Loading market data...

North Korea

North Korea

North Korea-linked hacking group Kimsuky has been assembling local AI environments using Ollama, GPT4All and Msty, according to security firm Genians. The setup lets the group run AI models without sending data to external services, a move that keeps its operations out of sight. Genians says the discovery is concrete evidence that Kimsuky is shifting from experimentation to using AI in actual attacks, including malware development and data analysis.

Why local AI matters

Running AI locally means conversation data never leaves the machine. That reduces the chance of exposure through third-party cloud services, which could tip off defenders or leave logs behind. The group also collected libraries and frameworks for AI integration, including LLaMaSharp, Microsoft Semantic Kernel and Microsoft Agents AI. Files tied to Whisper and faster-whisper, both speech-to-text tools, were found as well — tools that could be abused to process stolen or collected audio data.

Evidence in the tools

In GPT4All, investigators found a database linked to its LocalDocs feature. That suggests the group may have tried to connect documents to an AI system as a knowledge source. The combination of local models, document linking and speech-to-text points to a broader effort to fold AI into their workflow, not just a one-off test.

Crypto theft continues

The findings come as North Korea-linked attackers stole about $609 million in cryptocurrency in the first half of 2026, roughly 55% of the $1.1 billion lost across 212 incidents. The KelpDAO and Drift Protocol attacks were tied to TraderTraitor, a state-sponsored group associated with Lazarus, accounting for most of those losses. Humanity Protocol lost $32 million in an attack linked to the same group.

Separately, researcher ZachXBT reported that North Korean IT workers generated more than $3.5 million in crypto through fake developer identities and a coordinated payment system. The operation came to light after a hacker compromised one worker's device, exposing records tied to nearly 390 accounts. The scheme was pulling in about $1 million a month, with workers using forged documents and VPNs to hide their tracks.