Researchers Expose Kimsuky's Local AI Hacking Toolchain

TechNadu · x · 2026-08-14

South Korean security firm Genians discovered that the North Korea-linked hacking group Kimsuky is using local LLM tools and agent frameworks to enhance its attacks.

Researchers reconstructed the operation, dubbed 'Operation GitPower,' revealing that the group went beyond prompting for phishing copy. They built a local toolchain using Ollama, GPT4All, Msty, RAG tooling, and Cursor. Logs even exposed the operators' own ChatGPT queries, though no evidence of independent model training was found.

Related event: North Korean Hackers Kimsuky Deploy Local AI Toolkit(2 posts)→

Original post →

More from Safety

Safety channel →