North Korean hackers start using artificial intelligence to automate cyberattacks

illustrative, cyberattack / Curated Lifestyle
Фото: illustrative, cyberattack / Curated Lifestyle

The North Korea-linked hacking group Kimsuky has set up a local environment for working with large language models and is collecting technologies that could be used to automate cyberattacks. This is according to a report by the South Korean cybersecurity company Genians.

Experts found traces of the installation and use of Ollama, GPT4All, and Msty platforms in the hackers' infrastructure, which allow running language models directly on computers or servers without transmitting information to external AI services.

This approach makes it possible to process confidential or stolen documents without the risk of them falling into the hands of third-party companies. Genians estimates that the hackers may use AI to search for important information in large volumes of stolen data.

The group has also adapted retrieval-augmented generation, or RAG, technology. This allows the language model to generate responses based on documents uploaded to the system, including internal materials of targeted organizations.

In addition, researchers found components for developing AI agents, automating workflows, speech recognition, and converting audio recordings to text. This could potentially simplify the analysis of stolen recordings of phone calls and meetings.

Genians also logged the use of the Cursor code editor and software libraries, with which artificial intelligence capabilities can be integrated into programs and malicious software created by hackers.

Within the studied campaign, Kimsuky used phishing documents, likely created using generative AI. They dealt with investments, virtual assets, and other business topics, had naturally written text, and looked like genuine work materials.

Such documents were used to convince victims to open malicious files. After infection was triggered, the hackers could gain access to the device, collect information, and install applications for remote control.

The group also used GitHub and GitLab repositories as channels for managing infected devices and spreading malicious software. Its targets include foreign diplomatic missions, military and security agencies, as well as organizations related to virtual assets.

Kimsuky is linked to North Korea's Reconnaissance General Bureau. Genians believes the group is already moving from isolated experiments with generative AI to systematically incorporating such technologies into its operations.

At the same time, researchers found no evidence that North Korean hackers are independently training their own language models. Currently, they mostly study and adapt already available AI tools and software components to their needs.

Based on materials: Genians Security Center, Digital Today

analytics