Seoul: North Korea hackers have used artificial intelligence to strengthen cyberattacks targeting military, diplomatic and academic sectors across multiple regions.
The Seoul-based cybersecurity firm Genians identified a pattern of activity by the hacking group Kimsuky. The group links to North Korea’s intelligence services. The report, released on August 11, 2026, states that Kimsuky has deployed AI-generated documents in spear-phishing campaigns since 2026.
The attacks rely on malicious files designed to appear legitimate, often mimicking research papers or event invitations. Genians noted that AI tools enable rapid content creation, increasing the scale and efficiency of such attacks.
The use of artificial intelligence marks a significant shift in cyberattack methods across sectors. The firm added that AI allows threat actors to automate social engineering efforts. This development supports large-scale phishing operations across multiple sectors and increases the effectiveness of cyberattacks.

To reduce detection risks, Kimsuky used open-source tools like Ollama, GPT-4All and Msty. The tools allow large language models to run without internet access. This offline capability helps bypass monitoring systems and also limits exposure during operations.
Kimsuky and other state-linked groups from North Korea have been associated with multiple cyber incidents in recent years. Many attacks focus on financial gain and others target sensitive information across sectors.
The report emerged as concerns grow over misuse of artificial intelligence. Rapid advances in AI technology raise increasing concerns about security risks and possible misuse in cyber operations.
In a separate development, researchers in the United States have used AI to create new viruses not found in nature. The breakthrough offers medical possibilities but also raises concerns about misuse by North Korea hackers and other malicious actors.

