Security

Kimsuky builds offline AI stack for phishing and malware

3 min read

TL;DR Too Long; Didn’t read

North Korean hacker group Kimsuky has run an offline AI environment with Ollama, GPT4All and Msty on its attack servers since at least March 2026, South Korean security firm Genians reported on August 10, 2026, as part of Operation GitPower. The group drafts phishing lures and searches stolen documents without sending data to external providers. Investigators found no custom-trained model.

A hacker silhouette sits in front of a server rack; an isolated computer is cut off from a severed cloud representing external AI services, and a fishing hook made of chat bubbles grows out of it. Image generated with GPT Image 2

Key takeaways

  • Genians found 73 MD5 hashes, seven IP addresses, and 18 email addresses as indicators of the Kimsuky infrastructure.
  • The servers also ran the editor Cursor and the speech recognition tool Whisper from OpenAI.
  • North Korean spelling patterns in keyboard logs and Astrill VPN point to the Reconnaissance General Bureau.
  • Operation GitPower disguises malware as image files in public GitHub repositories and reloads AsyncRAT every 30 minutes.
  • Genians classifies Kimsuky as being in a learning and procurement phase, not as developers of their own AI models.
  • In 2025, the group already forged South Korean military IDs with AI-generated images for phishing campaigns.

Kimsuky has built its own offline infrastructure for generative AI, according to the South Korean security company Genians. The local language model tools Ollama, GPT4All, and Msty were running on the attack servers of the North Korean espionage group, connected to a database for full-text search in stolen documents. Genians published the analysis on August 10, 2026, and attributes the find to the ongoing campaign Operation GitPower.

Genians finds complete local AI toolchain

On the examined systems, the analysts from Genians discovered several layers of a local AI environment. In addition to Ollama, whose startup process automatically creates an SSH key in the administrator account, installation files of GPT4All along with a RAG database and the desktop application Msty were found. Additionally, several installers of the AI programming editor Cursor and tools for speech recognition, including Whisper and faster-whisper from OpenAI with a Korean training file, were present.

In developer libraries such as LLaMaSharp, Microsoft Semantic Kernel, and Microsoft.Agents.AI, as well as GPU acceleration packages for Nvidia graphics cards, the researchers see a continuous chain of local AI execution up to automated agents. However, Genians did not find a custom-trained language model or larger training datasets. The group claims to still be in a learning and procurement phase, where existing AI tools are being integrated rather than developed independently.

Operation GitPower disguises malware as image files

The technical framework of the campaign continues the FlowerPower attack series known since 2023 and begins with spear-phishing emails containing prepared ZIP archives. If a victim opens the included LNK file, a PowerShell command of about 3,800 characters starts, into which the attackers inserted 300 spaces to hide the actual malicious function from automated scanners. A custom Base64 decoder bypasses standard functions that security software often detects.

At the same time, the system downloads a real PDF file via the GitHub Raw API, while in the background, a scheduled task running every 30 minutes reloads the remote access software AsyncRAT. Several public GitHub repositories with files like apple.png or rabbit.png, which actually contain malware, serve as camouflage. In the course of the analysis, Genians published 73 MD5 hashes, seven IP addresses, and 18 email addresses as indicators for security teams.

Linguistic traces point to North Korea

Several technical details attribute the campaign to the North Korean Reconnaissance General Bureau, which also oversees Kimsuky, according to Genians. Reconstructed keystrokes revealed spellings that follow North Korean rather than South Korean orthography. Additionally, there is a device referred to as “Arirang” – a widely used tablet brand in North Korea – a Chinese version of the office software WPS Office, as well as the software Astrill VPN and AnyDesk, which are often associated with North Korean groups.

As early as 2025, Kimsuky had been noticed in phishing campaigns with ChatGPT-generated images of fake South Korean military IDs. Other North Korean groups are also increasingly targeting AI infrastructure: just in early August, CrowdStrike documented how the related group Stardust Chollima hijacked stolen access to commercial AI services. According to Reuters, the attribution of the campaign to Kimsuky and individual technical details could not be independently verified at the time of reporting.

It will be crucial whether the trend towards offline-operated AI tools continues among state-controlled groups: local models circumvent exactly those security filters that providers like OpenAI or Anthropic aim to use to prevent abuse through their cloud services. Genians announced that it will continue to monitor Kimsuky’s activities; however, the company has not yet provided a specific date for a follow-up analysis.

Frequently asked questions

What is the Kimsuky group?

Kimsuky is a North Korean espionage group that operates under the Reconnaissance General Bureau and has targeted diplomats, military, and cryptocurrency targets through spear-phishing for years.

Why do attackers use local instead of cloud AI models?

Offline-operated models like Ollama or GPT4All run without a connection to external providers, bypassing their abuse filters and logging.

Are specific victims of the current campaign known?

Genians does not name any individual affected organizations in the analysis but describes the technical infrastructure and indicators of the Operation GitPower campaign.

How do providers like OpenAI respond to the abuse of open AI tools?

There are currently no public statements from OpenAI, Ollama, or GitHub regarding this specific case.

How does Operation GitPower differ from the FlowerPower campaign?

Operation GitPower builds on the FlowerPower infrastructure known since 2023 but, according to Genians, adds a wide range of local AI tools for the first time.

Sources (3)
  1. Genians: Kimsuky Integrates AI into Attack Operations
  2. Reuters: North Korean hacking group builds AI tools for cyberattacks, report says
  3. The Hacker News: Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog