threat-intel
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
High
Summary
North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4All, and Msty being run on Kimsuky's infrastructure, alongside developer libraries and transcription tools. This represents a shift in Kimsuky's tactics, moving beyond relying on polished lures to proactively integrate AI into its attack workflow, as part of Operation GitPower.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
