North Korean state-sponsored hackers are increasingly leveraging artificial intelligence to enhance their cyberattack operations, according to findings released by a South Korean cybersecurity firm. The hacking group Kimsuky, which maintains connections to North Korea’s intelligence apparatus, has been systematically deploying AI-generated documents as part of sophisticated spear-phishing campaigns targeting military, diplomatic, and academic institutions since 2026.
The attacks exploit AI technology to streamline the production of convincing fraudulent files that mimic legitimate documents such as research papers and official invitations. To minimize exposure, Kimsuky has relied on offline large language model tools including Ollama, GPT-4All, and Msty. According to cybersecurity analysts, this approach demonstrates how AI enables threat actors to automate and scale social engineering operations at unprecedented levels, moving beyond simple document manipulation.
Experts emphasize that this development reflects a troubling trend affecting all malicious actors globally. Intelligence analysts note that artificial intelligence has fundamentally lowered barriers to entry for cybercriminals, eliminating the need for specialized technical expertise. As generative AI technology continues advancing rapidly, cybersecurity professionals warn that AI-assisted attacks will become increasingly common, representing one of the decade’s primary security challenges.
North Korean hacking operations have a documented history of major cyber incidents, including the 2014 Sony Pictures breach. Recent data indicates these state-linked groups stole over $2 billion in cryptocurrency during the first nine months of 2025 alone.
