Kimsuky Goes Offline: North Korean Spies Build Their Own Private AI Toolkit
South Korean researchers say the Kimsuky group has stopped relying on public chatbots and is now running AI on its own servers to sharpen phishing and speed up malware writing.

Key points
- Genians, a South Korean security firm, says North Korea's Kimsuky group is now running artificial intelligence models on its own servers instead of using public services like ChatGPT.
- The hackers have wired AI tools into local document collections so they can search, summarise and rewrite stolen files at speed.
- Investigators found open-source AI components staged on Kimsuky infrastructure, suggesting plans to bake AI directly into malware.
- The shift makes the activity harder to spot, because there are no logs sitting with a chatbot provider for investigators to subpoena.
- Targets remain South Korean government, academic and defence contacts, hit mainly through spear-phishing emails.
North Korea's spies have decided the public chatbot era is over for them.
Kimsuky, one of Pyongyang's busiest hacking teams, has started running artificial intelligence, meaning software that can read, write and answer questions like a human, on machines it controls directly. That is the finding from South Korean security firm Genians, which has been tracking the group's tooling.
The change matters because it removes a witness. When hackers use a service like ChatGPT, the provider keeps records. Run the same kind of model on your own server and no outsider sees the prompts, the drafts, or the stolen documents you fed in.
What has Kimsuky actually built?
A private, in-house AI setup wired to its own stolen files. Genians describes a stack of open-source AI parts pulled together on Kimsuky-controlled systems, including tools that let a language model search through a folder of documents and answer questions about them.
That pattern is called retrieval-augmented generation, which is a fancy name for a simple trick: point the AI at a specific pile of files first, so its answers come from those files rather than from general knowledge. For an espionage crew sitting on gigabytes of pilfered emails and reports, that is a fast way to find what matters.
Genians also found components associated with building AI features into malicious software itself. The hackers are not just using AI to help write attacks. They are collecting the pieces to put AI inside them.
Who is Kimsuky and who do they hit?
Kimsuky is a North Korean state-backed group focused on intelligence gathering. Their usual targets sit in South Korea: government officials, think tanks, university researchers, and people working on defence or nuclear policy. Journalists and North Korean defectors have been hit too.
The group's standard opening move is spear-phishing, which is a targeted fake email crafted to look like it comes from a colleague, a reporter, or a conference organiser. Click the attachment or the link, and malware lands on your machine.
AI makes that opening move sharper. A model trained or tuned on stolen correspondence can imitate a specific person's tone, in Korean or English, without the awkward phrasing that used to give these lures away.
Why does running AI offline change the picture?
It breaks the paper trail. Earlier reporting, including from The Hacker News, has documented North Korean operators caught prompting commercial chatbots for phishing help and code. Those cases surfaced because providers noticed and acted.
Self-hosted models sit outside that view. There is no vendor to file an abuse report, no account to suspend, no prompt history for investigators to pull.
| Detail | What Genians reports |
|---|---|
| Group | Kimsuky (North Korea, state-backed) |
| Setup | Self-hosted AI models on group-controlled servers |
| Feature | Document search and summarisation over local files |
| Direction | AI components staged for embedding into malware |
| Primary targets | South Korean government, academic and defence sectors |
What should people at risk do?
If your work touches Korean peninsula policy, defence research, or defector support, treat unexpected email attachments as suspect even when the sender looks familiar. Verify through a second channel, a phone call or a known chat account, before opening anything.
Turn on multi-factor authentication, which is the extra code or app prompt after your password, on email and cloud storage. Keep browsers and Office software patched. Report odd messages to your security team quickly, because early reports are what let defenders spot a campaign while it is still small.



