Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Putting frontier cyber models in more trusted hands

    August 10, 2026

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    August 10, 2026

    Hormuz Nerves Cost Bitcoin $65,000 Mark Despite Solid Institutional Flows

    August 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Putting frontier cyber models in more trusted hands
    • Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds
    • Hormuz Nerves Cost Bitcoin $65,000 Mark Despite Solid Institutional Flows
    • New GLP-1 pill delivers up to 12% weight loss in 36 weeks
    • Sudan’s army chief holds unannounced talks on national dialogue | Sudan war News
    • Europe’s scorching summer is erasing its economic growth, says report – POLITICO
    • What could Andy Burnham do to block early release of PC Andrew Harper’s killers? | UK criminal justice
    • From ticket booking fees to shrinkflation, six other ways Burnham could cut cost of living | UK cost of living crisis
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 10, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 10, 2026Cyber Espionage / Artificial Intelligence

    North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.

    South Korean security firm Genians says it uncovered the setup after months of tracking and log analysis on infrastructure tied to Kimsuky, a hacking unit under North Korea’s Reconnaissance General Bureau.

    Genians found no evidence that the group had trained an AI model of its own, and the firm does not offer that as reassurance. It describes an actor in a “research and knowledge acquisition” stage, assembling and testing existing tools rather than making new models, with the apparent aim of folding AI through the operation, from writing malware to analyzing data.

    For an intelligence unit that has spent years phishing government, research, and other strategic targets, that points to attacks that are quicker to prepare and harder to spot.

    With nothing here to patch, the weight lands on defenders. Once AI writes the bait, the tells they once relied on weaken: stilted translation, clumsy formatting, spelling mistakes. What an intrusion does on the machine becomes the thing to watch.

    Genians’ report tells defenders to correlate LNK execution, PowerShell, hidden scheduled tasks, GitHub traffic, and later payload activity instead of judging a lure mainly by how polished it looks.

    Cybersecurity

    The core evidence is tools for running language models offline: Ollama, GPT4All and Msty, all found on infrastructure Genians linked to the group. The report says they were run or configured, not merely downloaded: Ollama generated the keys created on first launch, while GPT4All carried a configured localdocs_v3.db, the database used by its LocalDocs retrieval-augmented generation (RAG) feature.

    RAG lets a model answer from a private collection of documents. The database is evidence that the actor tried to connect documents in its possession to an AI system; it does not establish that those documents were stolen.

    The researchers separately recovered an operator request to check a data set for wallet details, Gmail credentials and site-registration history, ending, “The more detailed the analysis, the better. Please do not do it haphazardly.” The report could not confirm that this particular request was submitted to an AI service.

    The group did not stop at ready-made apps. On the same infrastructure, the firm found developer libraries including LLaMaSharp, Microsoft’s Semantic Kernel and Microsoft.Agents.AI, components for building AI functions into custom C# and .NET software.

    It also found OpenAI’s Whisper speech-to-text files with a guide on extracting text from audio, and active traces of Cursor, an AI-powered coding editor. None of these tools is exotic. What is new is a nation-state espionage group assembling them on purpose to push AI deeper into its own attack workflow.

    The activity extends a Kimsuky campaign Genians calls Operation GitPower, which abuses GitHub repositories as command channels in an LNK-to-PowerShell infection chain and has distributed encrypted AsyncRAT payloads disguised as image files

    Cybersecurity

    Fortinet separately documented the broader GitHub-C2 pattern in April in attacks targeting South Korean users. That report corroborates the surrounding technique family, not Genians’ new local-AI artifacts; Reuters said the new findings could not be independently verified.

    The newly observed offline stack (the local models, RAG database, and transcription tools) has not been shown running against a victim in the reporting to date, and no GitPower victim count has been disclosed. Set against the broader “AI attack tools” framing, that is a narrower near-term change than the label implies, with the groundwork for automating parts of the operation still being laid.

    Genians ties the operation to Kimsuky using overlaps with earlier campaigns, infrastructure clues, and North Korean vocabulary recovered from operator logs. The U.S. Treasury, which sanctioned Kimsuky in 2023, describes it as subordinate to the Reconnaissance General Bureau and primarily focused on intelligence collection.

    The step also fits a pattern Genians flagged in 2025, when it linked Kimsuky to a spear-phishing attack that used ChatGPT-generated images of South Korean military employee ID cards.

    automate Boost Builds development Kimsuky Malware offline Phishing Stack
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns

    When Credentials Are No Longer Enough: Device Trust in the AI Era

    Member of The Com sent to prison for blackmail, sextortion

    Valve notifies Steam hardware customers of a data breach

    How to detect OAuth client ID spoofing in Microsoft Entra ID before account takeover

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Putting frontier cyber models in more trusted hands

    August 10, 2026

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    August 10, 2026

    Hormuz Nerves Cost Bitcoin $65,000 Mark Despite Solid Institutional Flows

    August 10, 2026

    New GLP-1 pill delivers up to 12% weight loss in 36 weeks

    August 10, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Putting frontier cyber models in more trusted hands

    August 10, 2026

    Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

    August 10, 2026

    Hormuz Nerves Cost Bitcoin $65,000 Mark Despite Solid Institutional Flows

    August 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.