Kimsuky builds AI attack stack to target crypto after 2B$ 2025 haul

Share

On August 10, 2026, South Korean cybersecurity firm Genians confirmed that Kimsuky, a North Korean state-sponsored hacking group, has set up three local AI environments to automate its cyberattacks against the crypto and financial sectors. This industrialization marks a turning point: phishing lures, malware development and analysis of stolen data are now handled by language models running offline, beyond the reach of major cloud providers.

🔑 Key takeaways

  • Three local LLMs (Ollama, GPT4All, Msty) identified on Kimsuky’s infrastructure
  • Phishing lures mimicking a South Korean AI-powered investment platform
  • $2.02B in crypto stolen by North Korean hackers in 2025, including $1.5B from the Bybit hack
  • $100M Coldcard wallet exploit linked to an AI-discovered vulnerability
  • US Treasury sanctions imposed in 2023, confirmed links to Emerald Sleet and Velvet Chollima

A local, offline AI stack

According to Genians’ report published on August 10, 2026, Kimsuky has assembled a full AI stack on its own machines, independent of any cloud API (application programming interface). The three tools identified — Ollama, GPT4All and Msty — run language models directly on operator workstations, with a retrieval-augmented generation (RAG) layer that indexes internal documents to answer specialized queries.

This architecture offers two strategic advantages. First, it removes any transfer of sensitive data to OpenAI, Anthropic or Google, bypassing the access bans already imposed by Microsoft on the “Emerald Sleet” sub-group. Second, RAG enables the injection of specialized corpora — target lists, fintech vocabulary, South Korean investment document templates — directly into model contexts. The group has also collected LLM integration libraries, the Cursor programming assistant and voice recognition tools, forming a complete chain from development to execution.

From artisanal phishing to mass weapon

Genians researchers identified several AI-generated phishing documents written in Korean and English that replicate with striking realism the reports of a South Korean AI-powered investment platform. Layout, tone, typography and financial vocabulary are aligned to the pixel with official content, which significantly reduces detection rates by victims and anti-spam filters.

These lures target three segments: crypto-asset holders, investment strategy advisors, and fintech product teams. Once the attachment is opened, the BabyShark payloads (a Windows system profiling and credential-stealing script observed since 2018) and AppleSeed (a backdoor active since 2019 and tracked by ASEC) take over. The AIDE platform of the Global Cyber Alliance captured several waves of repeated connections linked to these two families, confirming that they remain operational pillars of Kimsuky despite their age.

« This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities. »

Genians, report dated August 10, 2026

$2.02 billion stolen in 2025

Hackers affiliated with Pyongyang remain the primary threat against crypto platforms. According to Chainalysis, they stole $2.02 billion in cryptocurrencies in 2025, including $1.5 billion in the hack of exchange Bybit — one of the largest digital heists in history. The March 2024 UN Security Council report values the cumulative amount diverted between 2017 and 2023 at $3 billion, used to fund North Korean weapons programs.

Several landmark attacks

YearTargetAmountMethod
2025Bybit$1.5BInfrastructure compromise
2025Coldcard wallets$100MAI-identified software flaw
2024South Korean crypto forumSeveral M$Email phishing
2017-2023Multiple exchanges$3B (cumulative)Phishing, insider intrusion

The Coldcard episode illustrates the new doctrine: according to several experts, the $100M exploit on these Bitcoin hardware wallets relies on an obscure vulnerability discovered by an AI model, which reportedly reduced to a few days a reverse-engineering task that usually takes months.

« AI is supercharging hackers’ ability to find software vulnerabilities faster than traditional security can patch them. »

Illia Polosukhin, co-founder of NEAR Protocol

A global infrastructure under surveillance

Data published by the Global Cyber Alliance from its AIDE platform maps a particularly dispersed attack infrastructure. The sensors detected a persistent Internet Explorer 11 user-agent signature — “Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko” — in command-and-control traffic, a signature recognized as an indicator of compromise (IoC) by CISA and the FBI.

In terms of volume, servers hosted in Panama lead the way, followed by the United States, the United Kingdom and Germany. This geographic dispersion, combined with the use of cloud providers, telecom operators and local ISPs, significantly complicates the attribution and neutralization of Kimsuky’s assets.

Distribution of identified hosts

CountryRelative share of C2 trafficInfrastructure type
PanamaHighest concentrationCommercial hosting
United StatesHighCloud, ISP
United KingdomMediumHosting, ISP
GermanyMediumHosting, ISP

Sanctions, cooperation and proactive defense

The US Treasury Department placed Kimsuky on its sanctions list in 2023, describing it as a cyber-espionage group under the control of the Pyongyang regime. CISA, for its part, has tracked it since 2012 as a global intelligence collection actor, primarily targeting South Korean agencies and specialists in the South Korea–United States–Japan triangle.

In February 2024, South Korea published its revised National Cybersecurity Strategy, built around proactive defense, critical infrastructure hardening and international cooperation. The document explicitly plans the integration of AI-powered systems for real-time threat detection and response, as well as the creation of an AI Security Institute by the end of 2024. In April 2023, Washington and Seoul launched a Strategic Cybersecurity Cooperation Framework, followed in December 2023 by trilateral talks with Tokyo.

« The North Koreans are some of the most creative and innovative in leveraging emerging tech. »

Anne Neuberger, US Deputy National Security Advisor for cyber and emerging tech

Toward the industrialization of state-sponsored cybercrime

Kimsuky’s shift to persistent, local AI environments is no mere anecdote: it signals the end of one-off experiments and the start of a reproducible attack chain, updated at the pace of open-source models. By removing dependence on cloud APIs, the group bypasses the bans imposed by Microsoft on Emerald Sleet and gains operational autonomy — a major tactical advantage in a context of tightened sanctions.

For crypto and finance players, the implications are twofold. In the short term, phishing lures will become even more realistic, requiring tougher authentication procedures (hardware MFA, multi-party signatures on exchange treasuries). In the medium term, AI-assisted vulnerability discovery will shorten the cycle between bug disclosure and exploitation, forcing wallet and smart contract publishers to accelerate their audits and bug bounty programs. The race between defenders and attackers has just changed scale.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles