State-sponsored North Korean hackers are using artificial intelligence (AI) to bolster cyber attacks against military, diplomatic, and academic targets, according to a new report.
The report, released Monday by South Korean cybersecurity firm Genians, said the hacker group Kimsuky, linked to North Korea's intelligence agency, has used AI-generated documents in a series of spear-phishing attacks since 2026.
The attacks used AI to automate the creation of malicious files disguised as legitimate documents, such as research reports and invitation letters, per Seoul-based Genians.
To avoid detection, Kimsuky used open-source tools like Ollama, GPT-4All, and Msty to run large language models without internet connectivity.
"AI can produce highly polished documents on a wide range of topics in a short time, making it an effective tool for threat actors," Genians noted.
"This shift is notable because it goes beyond changing how lure documents are crafted; it suggests AI can enable automation and large-scale production of social engineering attacks."
Kimsuky and other North Korea-linked groups have been accused of numerous cyber attacks in recent years, many aimed at financial gain. According to a report by British blockchain analysis firm Elliptic, North Korean hackers stole over $2 billion in cryptocurrency in the first nine months of 2025.
In 2014, the U.S. identified North Korea as the culprit behind the cyber attack on Sony Pictures, tied to the comedy "The Interview," which mocked North Korean leader Kim Jong Un.
Jenny Town, a senior fellow at the Stimson Center in Washington, said the development is not surprising given North Korea's history of cyber attacks. "North Korean hackers and programmers are fully capable of using and exploiting various AI tools to enhance their operations. This is a new reality for all threat actors; North Korea is no exception."
The cybersecurity report comes amid rapid AI advances raising concerns about potential harm from malicious actors and systems spiraling out of control. Over the weekend, U.S. researchers announced they had used AI to create a virus not found in nature, offering hope for medical progress but also sparking concerns about danger.
Mark T. Hofmann, a crime and intelligence analyst specializing in cybercrime, said AI has drastically changed the cybercrime landscape by lowering barriers for malicious actors. "You no longer need hacking skills or a master's degree in computer science. All you need is a computer and motivation," Hofmann said. He emphasized: "Threat actors worldwide will increasingly use generative AI and, worse, AI agents to accelerate cyber attacks. The dark side of AI is one of the main challenges of this decade. AI-assisted cyber attacks will become commonplace."