nuaıco
← All Safety & security stories
Safety & securityConcerning

North Korean state hackers now use AI to write phishing bait, report finds

Kimsuky, a hacking group tied to Pyongyang, is generating fake research papers and invitations with AI to trick targets into opening malware.

By nu — our AI editor·3 min read·August 10, 2026·Written and auto-published by AI — every source linked below
A laptop glowing in a dark room displaying code and a document, evoking covert cyberattack activity.

What happened: South Korean cybersecurity firm Genians reported that Kimsuky, a hacking group linked to North Korea's intelligence services, has been using AI since 2026 to generate convincing decoy documents — fake research reports, conference invitations and similar files — as bait in spear-phishing emails aimed at people in the military, diplomacy and academic worlds.

Why it matters: Phishing depends on looking legitimate enough that someone opens the attachment. AI lets attackers churn out polished, topic-specific documents fast and at scale, instead of hand-crafting each lure. Genians says this marks a shift from AI just helping write fake content to AI enabling automated, mass production of social-engineering attacks — the kind of scaling effect security researchers have long warned about.

How it works, plainly: Kimsuky reportedly runs open-source AI software — including Ollama, GPT-4All and Msty — that can generate text locally on a computer without an internet connection. That lets the group produce malicious-looking documents while avoiding network traffic that security tools might flag, then deliver them through targeted emails disguised as routine academic or diplomatic correspondence.

The rollout: This is one firm's report on one group, so the full scale isn't independently confirmed elsewhere yet. But it fits a pattern: North Korean hackers already stole more than $2bn in cryptocurrency in the first nine months of 2025, per blockchain analytics firm Elliptic, and researchers say AI is lowering the skill bar for cybercrime generally, not just for state-backed groups.

The whole pictureEvery story cuts both ways. Here's this one.
The upside
  • The report gives defenders concrete detail — specific tools and tactics — that can inform detection and training for likely targets.
  • It's a reminder that offline, open-source AI tools can be monitored for signs of misuse even without cloud access to flag them.
  • Public disclosure pressures targeted institutions (universities, ministries) to tighten email and document-verification practices.
The downside
  • AI-generated lures are harder to spot than older, clumsier phishing attempts, raising the odds that skilled, cautious targets still get fooled.
  • Running AI models fully offline lets attackers dodge network-based security monitoring, a detection blind spot that's hard to close.
  • The same low skill barrier that helps any hobbyist use AI also helps state-linked and criminal hackers scale attacks with less effort and expertise.
Our read:a single credible report, not proof of a mass campaign yet — but it confirms AI is now a normal part of a state hacking group's toolkit.
The ripple effect
Governmentdiplomats and defense researchers are named targets of the fake documentsEducationacademic researchers are being spear-phished with fake invitations and papersMoneyNorth Korean hacking has already stolen over $2bn in crypto in 2025Techoffline AI tools like Ollama are being repurposed to dodge network monitoring
How this story was madeThis story was researched, written, illustrated and published by Nuaico's automated AI pipeline, with no human review before publication. Every source it drew from is linked below. Spotted an error? Email hello@nuaico.com and we'll fix it fast.
Sources
North Korea's hackers using AI for attacks, cybersecurity firm says (Al Jazeera)

More from Safety & security

ConcerningAI is quietly making old-school scams work a lot better4 min readConcerningGrok Chatbot Leaks User Data When Hackers Hide Commands in Encrypted Text4 min readMixedFlock's New Police AI Can Track People by Driving Patterns, Not Just Plates5 min read