Economy
🇰🇷 South KoreaSouth Korea: the Attacks Used AI to Automate the Creation of Malicious Files Disguised As Legitimate Documents Such As Research Reports

North Korean state-backed hackers are using artificial intelligence to bolster cyberattacks against military, diplomatic and academic targets, according to a report by South Korean cybersecurity firm Genians. The hacking group Kimsuky, linked to North Korea's intelligence services, has used AI-generated documents in a pattern of spear-phishing attacks since 2026, the Seoul-based firm said in a report released Monday. The attacks used AI to automate the creation of malicious files disguised as legitimate documents such as research reports and invitations.
To avoid detection, Kimsuky used open-source tools including Ollama, GPT-4All and Msty to run large language models without an internet connection. "AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors, Genians said. "This change is noteworthy because it goes beyond a shift in how decoy documents are created and demonstrates that AI can enable the automation and large-scale production of social engineering attacks.
Kimsuky and other North Korean state-linked groups have been blamed for numerous cyberattacks in recent years, many aimed at extracting financial gains. North Korean hackers stole cryptocurrency worth more than $2bn in the first nine months of 2025, according to British blockchain analytics firm Elliptic. In 2014, US authorities identified North Korea as the culprit in the hacking of Sony Pictures, which drew Pyongyang's ire by lampooning leader Kim Jong Un in the comedy film "The Interview.
Jenny Town, senior fellow at the Stimson Center in Washington, DC, said the development was not surprising given North Korea's history of cyberattacks. "North Korea's hackers and programmers are more than capable of utilising and exploiting various AI tools to enhance their efforts, Town told Al Jazeera. "This is a new reality of all threat actors; North Korea is no exception.
The report comes as rapid advances in AI stoke fears about potential harm by bad actors and systems going rogue. US researchers last week announced they used AI to create viruses not found in nature for the first time, raising hopes for medical advances but also concerns about dangers. Mark T. Hofmann, a criminal and intelligence analyst specialising in cybercrime, said AI had led to a seismic shift by lowering the bar for malicious activity.
"You no longer need hacking skills or a master's degree in computer science. All you need is a computer and a motive, Hofmann told Al Jazeera. "Threat actors all around the world will use more and more generative AI and, much worse, AI agents to accelerate their cyberattacks, he added.
"The dark side of AI is one of the main challenges of this decade. AI-supported cyberattacks will become a regular phenomenon.
Source: Al Jazeera English
Most read in this category
Loading article…