None
EN
North Korean Hackers Are Using Local AI to Make Crypto Phishing Harder to Spot
['Danielle Du Toit', 'Danielle Du Toit Is A Crypto Security', 'Investigations Journalist Covering Digital-Asset Crime', 'Protocol Exploits', 'Scams', 'Enforcement Actions', 'Consumer Protection. With An Honours Degree In Criminology', 'She Examines How Crypto Attacks Happen', 'How Stolen Funds Move', 'How Regulators']
Coinpaper
state-linked hacking group Kimsuky is building local artificial intelligence environments that researchers say could improve phishing campaigns, malware development and attack automation.
South Korean cybersecurity firm Genians it found evidence that Kimsuky configured local large language model environments using Ollama, GPT4All and Msty.
The group also experimented with retrieval-augmented generation, or RAG, AI coding assistant Cursor, speech-to-text software and tools for developing AI agents.
Genians made sure to mention that it found evidence of Kimsuky integrating existing AI technologies, rather than training proprietary models.
For crypto companies, the research suggests that obvious spelling mistakes and poorly formatted documents are becoming even less useful as phishing warning signs.