Kimsuky Goes Offline: North Korean Spies Build Their Own Private AI Toolkit
South Korean researchers say the Kimsuky group has stopped relying on public chatbots and is now running AI on its own servers to sharpen phishing and speed up malware writing.

Key points
- Genians, a South Korean security firm, says North Korea's Kimsuky group is now running artificial intelligence models on its own servers instead of using public services like ChatGPT.
- The hackers have wired AI tools into local document collections so they can search, summarise and rewrite stolen files at speed.
- Investigators found open-source AI components staged on Kimsuky infrastructure, suggesting plans to bake AI directly into malware.
- Running models offline removes the provider logs that investigators have previously used to catch North Korean operators.
- Targets remain South Korean government, academic and defence contacts, hit mainly through spear-phishing emails.
North Korea's spies have decided public chatbots are no longer useful to them.
Kimsuky, one of Pyongyang's busiest hacking teams, has started running artificial intelligence on machines it controls directly. That's the finding from South Korean security firm Genians, which has been tracking the group's tooling. We first covered Kimsuky in May 2026, when the crew was spoofing Webex pages and dropping new implants on military networks; what Genians describes now is a significant step up in operational discipline.
The change matters because it removes a witness. When hackers use a service like ChatGPT, the provider keeps records. Run the same kind of model on your own server and no outsider sees the prompts or the stolen documents you fed in.
What has Kimsuky actually built?
A private AI setup wired to its own stolen files. Genians describes a stack of open-source components pulled together on Kimsuky-controlled systems, including tools that let a language model search through a folder of documents and answer questions about them.
That pattern is called retrieval-augmented generation: point the AI at a specific pile of files first, so its answers draw from those files rather than general knowledge. For an espionage crew sitting on gigabytes of pilfered emails and reports, that's a fast way to find what matters.
Genians also found components associated with building AI features into malicious software. The hackers aren't just using AI to help write attacks. They're collecting the pieces to put AI inside them.
Who is Kimsuky and who do they hit?
Kimsuky is a North Korean state-backed group focused on intelligence gathering. Their usual targets sit in South Korea: government officials, defence researchers and North Korean defectors. Journalists have been hit too.
The group's standard opening move is spear-phishing, a targeted fake email crafted to look like it comes from a known colleague or conference organiser. Click the attachment or the link, and malware lands on your machine.
AI makes that opening move sharper. A model tuned on stolen correspondence can imitate a specific person's writing style without the awkward phrasing that used to give these lures away.
Why does running AI offline change the picture?
It breaks the paper trail. Earlier reporting, including from The Hacker News, documented North Korean operators caught prompting commercial chatbots for phishing help and code. Those cases surfaced because providers noticed and acted.
Self-hosted models sit outside that view. There's no vendor to file an abuse report, no account to suspend, no prompt history for investigators to pull.
| Detail | What Genians reports |
|---|---|
| Group | Kimsuky (North Korea, state-backed) |
| Setup | Self-hosted AI models on group-controlled servers |
| Feature | Document search and summarisation over local files |
| Direction | AI components staged for embedding into malware |
| Primary targets | South Korean government, academic and defence sectors |
Should you worry?
If your work touches Korean peninsula policy, defence research or defector support, treat unexpected email attachments as suspect even when the sender looks familiar. Verify through a second channel, a phone call or a known messaging account, before opening anything.
Turn on multi-factor authentication, the extra code or app prompt after your password, on email and cloud storage. Keep browsers and office software patched. Report odd messages to your security team quickly, because early reports are what let defenders spot a campaign while it's still small.
The real watch item here isn't the AI itself. It's that Kimsuky is now building infrastructure designed to leave no trace with any third party, which means the early-warning signals defenders have relied on are quietly disappearing.



