North Korean state hackers now use AI to write phishing bait, report finds
Kimsuky, a hacking group tied to Pyongyang, is generating fake research papers and invitations with AI to trick targets into opening malware.
What happened: South Korean cybersecurity firm Genians reported that Kimsuky, a hacking group linked to North Korea's intelligence services, has been using AI since 2026 to generate convincing decoy documents — fake research reports, conference invitations and similar files — as bait in spear-phishing emails aimed at people in the military, diplomacy and academic worlds.
Why it matters: Phishing depends on looking legitimate enough that someone opens the attachment. AI lets attackers churn out polished, topic-specific documents fast and at scale, instead of hand-crafting each lure. Genians says this marks a shift from AI just helping write fake content to AI enabling automated, mass production of social-engineering attacks — the kind of scaling effect security researchers have long warned about.
How it works, plainly: Kimsuky reportedly runs open-source AI software — including Ollama, GPT-4All and Msty — that can generate text locally on a computer without an internet connection. That lets the group produce malicious-looking documents while avoiding network traffic that security tools might flag, then deliver them through targeted emails disguised as routine academic or diplomatic correspondence.
The rollout: This is one firm's report on one group, so the full scale isn't independently confirmed elsewhere yet. But it fits a pattern: North Korean hackers already stole more than $2bn in cryptocurrency in the first nine months of 2025, per blockchain analytics firm Elliptic, and researchers say AI is lowering the skill bar for cybercrime generally, not just for state-backed groups.
