North Korean hackers use AI to boost crypto attacks
North Korean hackers use AI and local LLMs to automate crypto attacks, stealing $643M in early 2026 and launching advanced phishing and malware campaigns targeting finance.
North Korean hacking groups, notably Kimsuky and APT45, are rapidly advancing their cyberattack strategies by integrating artificial intelligence and large language models (LLMs) into their operations. Cybersecurity firms have observed these groups deploying local LLM environments with tools like Ollama, GPT4All, and Msty. This setup enables them to automate intelligence gathering, malware development, and attack execution without relying on commercial cloud services. The adoption of retrieval-augmented generation systems and AI coding assistants, such as Cursor, further enhances their ability to craft sophisticated phishing lures, generate fraudulent documents, and exploit vulnerabilities at scale. In the first half of 2026, North Korea-linked hackers were responsible for stealing $643 million in cryptocurrency, accounting for 66% of global crypto hacking losses. Evidence also points to the use of AI-generated malware, like HelloDoor, and the creation of convincing phishing documents targeting the crypto and financial sectors. This shift toward highly automated, AI-driven attacks marks a significant evolution from traditional spearphishing, making detection and prevention increasingly challenging for security teams.