Defenders should judge lures by what happens after the click, not how polished the bait looks: North Korea’s Kimsuky espionage group has begun running AI models on its own servers, according to South Korean security firm Genians.
Genians spent months logging activity on infrastructure it ties to Kimsuky, the espionage unit under North Korea’s Reconnaissance General Bureau. The firm found Ollama, GPT4All, and Msty were actually executed or configured rather than just fetched, and the GPT4All install carried a populated localdocs_v3.db, the store behind its LocalDocs retrieval feature. That setup suggests the operators tried to feed documents they held into an AI assistant.
A separate message from an operator requested an examination of a data set, looking for wallet details, Gmail credentials, and site-registration history. It closed with the line “The more detailed the analysis, the better. Please do not do it haphazardly.” Whether that request ever reached an AI service is unconfirmed, and Genians saw no sign the group trained its own model.
The report argues that defenders should trace the full sequence, from LNK execution through PowerShell, hidden scheduled tasks, GitHub traffic, and the payload that follows, and stop grading a lure on how polished it looks. With AI drafting the lures, the old giveaways such as awkward translations and sloppy formatting become far weaker signals.
The group’s recent phishing emails use ZIP archives with malicious LNK files disguised as materials related to international events, research reports, or meeting requests, and in some cases AI was used to create lures related to virtual assets and finance. As with earlier campaigns, the intrusions use Git repositories for command-and-control infrastructure.
