Threat Intelligence

North Korean Hackers Go Offline with Custom AI to Supercharge Cyberattacks

The Hacker News · 10 Aug 2026
Key Takeaway As AI-powered phishing becomes more convincing, businesses should strengthen email verification processes and train staff to question urgent or unusual requests, even ones that look polished and legitimate.

Cybersecurity firm Genians has revealed that Kimsuky, a North Korean state-sponsored hacking group, has moved beyond using public AI chatbots and is now operating its own offline AI infrastructure. By running AI models on servers it controls, the group can search through stolen documents more efficiently and avoid the detection risks that come with using public AI platforms, which often log user activity.

According to the report, Kimsuky is also gathering software components needed to embed AI capabilities directly into its malware. This suggests the group is working towards automating parts of its attack process, including crafting more convincing phishing messages and speeding up malware development — tasks that previously required more manual effort from human operators.

This development signals a broader trend among sophisticated threat actors: adapting AI tools for offensive use while reducing their digital footprint. For small and medium businesses, this means phishing emails and scam messages may become harder to spot, as attackers use AI to make them more polished, personalised, and convincing. While Kimsuky primarily targets government and strategic organisations, the techniques it pioneers often filter down into broader cybercrime tools used against businesses of all sizes.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.