Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Kimsuky has assembled an offline AI stack on its own servers, with South Korean firm Genians finding tools Ollama, GPT4All, and Msty configured on infrastructure tied to the North Korea's Reconnaissance General Bureau unit.
- GPT4All carried a configured localdocs_v3.db database used by its LocalDocs RAG feature, evidence the group tried to connect documents in its possession to an AI system for retrieval-augmented generation.
- Genians also recovered developer libraries LLaMaSharp, Microsoft's Semantic Kernel, and Microsoft.Agents.AI on the same infrastructure, plus OpenAI's Whisper speech-to-text files and active traces of Cursor AI coding editor.
- The offline AI stack is in a 'research and knowledge acquisition' stage — Genians found no evidence Kimsuky trained its own model, and the tools have not been shown running against a victim in the reporting to date.
- Kimsuky ties the activity to Operation GitPower, which uses GitHub repositories as command channels in an LNK-to-PowerShell infection chain distributing encrypted AsyncRAT payloads disguised as image files.
- The U.S. Treasury sanctioned Kimsuky in 2023, describing it as subordinate to the Reconnaissance General Bureau and primarily focused on intelligence collection.
- Genians separately linked Kimsuky to a 2025 spear-phishing attack using ChatGPT-generated images of South Korean military employee ID cards.
Why it matters: The shift to offline AI strips phishing lures of the tells defenders have leaned on — stilted translation, spelling mistakes, clumsy formatting — forcing a pivot to behavioral signals like LNK execution, PowerShell, hidden scheduled tasks, and GitHub traffic. For the government and research targets Kimsuky has spent years phishing, the groundwork laid here could make attacks quicker to prepare and harder to spot.
Ask SkimNews



