Kimsuky has built its own offline infrastructure for generative AI, according to the South Korean security company Genians. The local language model tools Ollama, GPT4All, and Msty were running on the attack servers of the North Korean espionage group, connected to a database for full-text search in stolen documents. Genians published the analysis on August 10, 2026, and attributes the find to the ongoing campaign Operation GitPower.
Genians finds complete local AI toolchain
On the examined systems, the analysts from Genians discovered several layers of a local AI environment. In addition to Ollama, whose startup process automatically creates an SSH key in the administrator account, installation files of GPT4All along with a RAG database and the desktop application Msty were found. Additionally, several installers of the AI programming editor Cursor and tools for speech recognition, including Whisper and faster-whisper from OpenAI with a Korean training file, were present.
In developer libraries such as LLaMaSharp, Microsoft Semantic Kernel, and Microsoft.Agents.AI, as well as GPU acceleration packages for Nvidia graphics cards, the researchers see a continuous chain of local AI execution up to automated agents. However, Genians did not find a custom-trained language model or larger training datasets. The group claims to still be in a learning and procurement phase, where existing AI tools are being integrated rather than developed independently.
Operation GitPower disguises malware as image files
The technical framework of the campaign continues the FlowerPower attack series known since 2023 and begins with spear-phishing emails containing prepared ZIP archives. If a victim opens the included LNK file, a PowerShell command of about 3,800 characters starts, into which the attackers inserted 300 spaces to hide the actual malicious function from automated scanners. A custom Base64 decoder bypasses standard functions that security software often detects.
At the same time, the system downloads a real PDF file via the GitHub Raw API, while in the background, a scheduled task running every 30 minutes reloads the remote access software AsyncRAT. Several public GitHub repositories with files like apple.png or rabbit.png, which actually contain malware, serve as camouflage. In the course of the analysis, Genians published 73 MD5 hashes, seven IP addresses, and 18 email addresses as indicators for security teams.
Linguistic traces point to North Korea
Several technical details attribute the campaign to the North Korean Reconnaissance General Bureau, which also oversees Kimsuky, according to Genians. Reconstructed keystrokes revealed spellings that follow North Korean rather than South Korean orthography. Additionally, there is a device referred to as “Arirang” – a widely used tablet brand in North Korea – a Chinese version of the office software WPS Office, as well as the software Astrill VPN and AnyDesk, which are often associated with North Korean groups.
As early as 2025, Kimsuky had been noticed in phishing campaigns with ChatGPT-generated images of fake South Korean military IDs. Other North Korean groups are also increasingly targeting AI infrastructure: just in early August, CrowdStrike documented how the related group Stardust Chollima hijacked stolen access to commercial AI services. According to Reuters, the attribution of the campaign to Kimsuky and individual technical details could not be independently verified at the time of reporting.
It will be crucial whether the trend towards offline-operated AI tools continues among state-controlled groups: local models circumvent exactly those security filters that providers like OpenAI or Anthropic aim to use to prevent abuse through their cloud services. Genians announced that it will continue to monitor Kimsuky’s activities; however, the company has not yet provided a specific date for a follow-up analysis.


