cd /news/artificial-intelligence/north-koreas-kimsuky-turns-to-ai-as-… · home topics artificial-intelligence article
[ARTICLE · art-91356] src=cryptonews.net ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

North Korea’s Kimsuky Turns to AI as Crypto Firms Face New Threats

North Korea-linked threat actor Kimsuky has been setting up local AI environments using Ollama, GPT4All, and Msty, according to cybersecurity firm Genians, indicating the group is moving beyond experimentation to integrate AI into its cyberattack operations targeting cryptocurrency and financial sectors. Genians found evidence of document retrieval, automated agents, and speech-to-text tools like Whisper, suggesting AI could be used for malware development and data analysis. Separately, Blockaid reported that North Korean-linked attackers stole about $609 million in the first half of 2026, accounting for roughly 55% of the $1.1 billion lost across 212 crypto incidents.

read3 min views1 publishedAug 11, 2026
North Korea’s Kimsuky Turns to AI as Crypto Firms Face New Threats
Image: Cryptonews (auto-discovered)

Kimsuky has been setting up local AI environments as it looks for ways to bring artificial intelligence into its cyberattack operations. The North Korea-linked threat actor, which has frequently targeted the cryptocurrency and financial sectors, was found to have established local LLM environments using Ollama, GPT4All, and Msty.

Genians said the local approach prevents conversation data from being transmitted to external AI services, thereby reducing the risk of external exposure.

AI Added to Crypto Attack Playbook #

According to the report, the activity showed the group was building capabilities to integrate artificial intelligence into its attacks. In GPT4All, investigators detected a database linked to its LocalDocs feature. The cybersecurity firm said the evidence indicates that the threat actor may have attempted to connect documents in its possession to an AI system and use them as a knowledge source.

The group also collected libraries and frameworks that can integrate artificial intelligence into software. These included LLaMaSharp, Microsoft Semantic Kernel and Microsoft Agents AI. The components covered local AI execution, document retrieval, automated agents and integration with external AI services.

The investigation also found files related to Whisper and faster-whisper, speech-to-text tools. Genians said such tools could be abused to process and analyze material stolen or collected from compromised systems.

The company further added,

“This provides concrete evidence that the Kimsuky-affiliated threat actor is moving beyond one-off experimentation with AI and is continuously preparing to integrate the technology into actual attack capabilities, including malware development, data analysis, and the advancement of attack techniques.”

North Korea, Hackers and the Crypto Industry #

Zooming out, North Korea-linked attackers were responsible for more than half of the cryptocurrency stolen in the first half of 2026, according to Blockaid’s recent findings. The firm said DPRK-linked attackers stole about $609 million during the period, making up roughly 55% of the $1.1 billion lost across 212 incidents.

You may also like:

  • Micro Bitcoin (BTC) Holders Are Vanishing at the Fastest Pace Since December 2024
  • Arthur Hayes: AI Bubble Burst Could Trigger Bitcoin Rally
  • Coldcard Urges Users to ‘Carefully Move Funds’ as Exploit Losses Mount

The KelpDAO and Drift Protocol attacks were linked to TraderTraitor, a North Korean state-sponsored group associated with Lazarus. The two attacks accounted for most of the DPRK-linked losses. Humanity Protocol also lost $32 million in an attack tied to the same group. The findings highlight North Korea’s continued role in some of the biggest crypto thefts of 2026.

These operatives have also sought access from inside the industry. Prominent blockchain investigator ZachXBT had previously reported that North Korean IT workers generated more than $3.5 million in crypto through fake developer identities and a coordinated payment system. The operation came to light after a hacker compromised one worker’s device and exposed records tied to nearly 390 accounts.

The leaked data showed that the operation was bringing in about $1 million a month. Workers used fake identities and forged documents to secure jobs on different projects. Their payments were tracked through an internal platform, where workers reported their income and administrators managed transfers. Records from the compromised device also showed the use of VPNs and multiple fabricated personas. Chat logs revealed that dozens of workers were active in the same system.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @kimsuky 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/north-koreas-kimsuky…] indexed:0 read:3min 2026-08-11 ·