Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
Brief
◈ Key Findings
- Observed indications that the Kimsuky group built and operated local LLM environments using Ollama, GPT4All, and Msty.
- Assessed to be in the phase of accumulating technologies and capabilities to integrate AI across its overall attack operations.
- Identified indicators exhibiting North Korea-linked characteristics, such as "Arirang", "싸이트", "가입리력", and "로출되였는지".
- Continued targeted attacks against foreign diplomatic missions, as well as the military, security, and virtual asset sectors.
- Abused Git-based repositories as C2 infrastructure and distribution channels for encrypted AsyncRAT payloads.
- Highlighted the need to strengthen behavior-based EDR detection and threat hunting against the abuse of LNK files, PowerShell, and GitHub.
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
