North Korea’s hacking group Kimsuky is reportedly leveraging artificial intelligence to enhance its cyberattacks, primarily targeting military, diplomatic, and academic institutions. According to a recent report by South Korean cybersecurity firm Genians, Kimsuky has been utilizing AI-generated documents to conduct spear-phishing attacks since 2026. These attacks involve creating malicious files disguised as legitimate documents, such as research papers, making it increasingly difficult for targets to discern the threats.
The use of AI tools like Ollama and GPT-4All allows Kimsuky to produce polished documents quickly and in large quantities, automating social engineering attacks. This shift signifies a broader trend in cybercrime, where the barriers to entry are lowered, enabling even those without advanced technical skills to execute sophisticated attacks.
Experts warn that this development heralds a new era of cyber threats, as AI’s capabilities can be exploited by bad actors globally. The implications are significant; as AI technology becomes more integrated into cyber operations, the potential for widespread disruption increases. The ability to generate convincing decoys can lead to more successful breaches and data theft.
As AI continues to evolve, concerns are mounting about its dual-use nature, with researchers noting that while it can advance medical treatments, it also poses risks in the wrong hands. This trend underscores the urgent need for enhanced cybersecurity measures to combat the growing sophistication of cybercriminals using AI.
Source: Al Jazeera

