North Korea AI hackers scale spear-phishing, report says

North Korea-linked Kimsuky is using offline AI tools to automate spear-phishing against military, diplomatic and academic targets, a repoSources said.

Atlas Newsdesk ·

North Korea AI hackers scale spear-phishing, report says

A North Korea state-backed hacking group known as Kimsuky is using artificial intelligence to automate spear-phishing operations aimed at military, diplomatic, and academic personnel, according to a report released Monday by Seoul-based cybersecurity firm Genians.

Officials and analysts have long described spear-phishing as a central tactic in state-linked cyber operations, but the report says Kimsuky’s latest approach shifts the workload from manual, person-by-person social engineering to a more automated process that can produce malicious content at higher volume.

Genians details offline AI toolchain for malicious documents

Genians said the group has integrated large language models to generate convincing malicious documents at scale, including content designed to resemble legitimate research reports and invitations.

The report describes the use of open-source tooling— Ollama , GPT-4All , and Msty —to run language models in offline environments . By avoiding a need for internet connectivity, the actors can reduce exposure to certain forms of network-based detection while continuing to generate polished text.

From manual social engineering to automated production

Security researchers said the use of AI changes the economics of these operations by enabling faster drafting and iteration of lures, prompts, and attachments. Genians described this as a move toward automated, high-volume creation of malicious files rather than bespoke writing for each target.

The report also said the approach lowers technical barriers for cyber operations. In practical terms, analysts warned, that can shorten attack cycles by making it easier to produce deceptive materials that are coherent and tailored to professional contexts.

Broader context: heightened activity tied to Pyongyang-linked actors The findings come amid what the report described as a period of heightened cyber activity by Pyongyang-linked entities. Those entities were previously linked to the theft of over $2 billion in cryptocurrency during the first nine months of 2025, according to the source material referenced in the report.

While the Genians report focuses on document-driven deception and access operations, analysts said the wider pattern underscores how state-backed groups can apply multiple methods—credential theft, malware delivery, and financial cybercrime—depending on operational goals.

Defenders face growing pressure from AI-enabled lures

Security analysts warned that AI-supported cyberattacks are increasingly becoming a standard element of modern digital conflict, particularly where influence, intelligence collection, or access to restricted networks is at stake.

The repoSources said organizations in military, diplomatic, and academic sectors may need to adapt defensive strategies to account for automated social engineering. Genians’ assessment suggests the core risk is not only better-written phishing text, but also the ability to generate large volumes of plausible documents without relying on always-online infrastructure.

Implications

More stories