Artificial intelligence is rapidly transforming the world of cybersecurity, and not only because it allows companies and governments to improve their defense systems. The same technologies that are used to analyze large amounts of information, write code, automate processes, or generate texts can also be used by hacker groups to increase the speed and scale of their operations. One of the most recent examples comes from North Korea, where the hacking group Kimsuky is reportedly developing and using its own infrastructure based on artificial intelligence tools.
An investigation by the South Korean cybersecurity company Genians identified various artificial intelligence models, programming assistance tools, voice transcription systems, AI agents, and document-search technology known as RAG, short for Retrieval-Augmented Generation, in infrastructure related to Kimsuky. The combination of these technologies is particularly significant because it points to something broader than the occasional use of a simple chatbot. The group would be building a technological environment capable of supporting different stages of its espionage and cyberattack operations.
Kimsuky is not an unknown actor within the international cyber threat landscape. The group has been linked for years to North Korea and to campaigns targeting governments, institutions, organizations, and individuals connected to political, military, diplomatic, and technological affairs. The United States has identified it as part of Pyongyang-sponsored cyberespionage activities, while international investigations have also linked North Korean actors to information theft and operations aimed at obtaining financial resources.
The significance of the new scenario therefore lies in the incorporation of artificial intelligence into a capability that already existed. AI is not necessarily replacing human hackers; rather, it can become a multiplier of their capabilities. A tool that allows them to investigate targets more quickly, analyze documents, program more efficiently, or create more convincing communications can enable a relatively small group to carry out many more tasks with the same resources.

From Chatbots to Its Own Infrastructure
One of the most striking elements of the case is the diversity of artificial intelligence tools found. Genians’ investigation identified technologies such as Ollama, GPT4All, and Msty, as well as tools related to RAG, artificial intelligence agents, and programming assistants such as Cursor. Systems capable of converting voice into text also appeared, demonstrating that the group’s interest in artificial intelligence does not seem to be limited to a single function, but rather encompasses different applications of this technology.
The use of artificial intelligence models that can run locally is particularly important for a group dedicated to espionage. When an organization uses a commercial artificial intelligence platform, its requests normally pass through a provider’s infrastructure that may apply filters, record activity, or block certain behaviors. An artificial intelligence model installed directly on the user’s infrastructure, by contrast, allows data to remain within an environment controlled by the operator itself and allows artificial intelligence to be used without necessarily depending on an external service.
For an espionage group, this difference can be fundamental. Files obtained during an intrusion may include private communications, government documents, financial information, source code, or data related to sensitive investigations. If all that material can be processed locally using artificial intelligence tools, the attacker can reduce its dependence on external providers and use artificial intelligence to analyze large amounts of information without having to send it to commercial services.
The availability of open models also complicates efforts aimed at controlling the malicious use of artificial intelligence. A provider can close an account or prevent certain requests, but an attacker can turn to another service, install a different artificial intelligence model, or combine several artificial intelligence tools. This means that the fight against the criminal use of artificial intelligence cannot depend solely on the security measures applied by large technology companies, but also requires controls, research, and cybersecurity strategies capable of responding to the rapid evolution of artificial intelligence.
How Can AI Be Used in a Hacking Operation?
Artificial intelligence can intervene in practically every phase of a cyber operation. One of the first is target research, which may involve gathering information about employees, companies, technologies used, systems exposed on the internet, and relationships between different organizations. An artificial intelligence model can help organize this data, summarize documents, and find connections that would be difficult to identify manually.
Another important application of artificial intelligence is social engineering. Phishing attacks often depend on the attacker’s ability to convince a person that a communication is legitimate, so personalizing the message can increase its effectiveness. Artificial intelligence models make it possible to quickly generate texts adapted to different recipients, correct errors, change the tone of a communication, and produce content in different languages.
This capability of artificial intelligence can eliminate some of the traditional signals used to identify fraudulent messages. For years, grammatical errors, poor translations, and unnatural expressions have helped users become suspicious of certain emails. If artificial intelligence can produce much more natural messages adapted to the context of each victim, attacks may become more difficult to distinguish from authentic communications.
Artificial intelligence can also be used to analyze information obtained during an intrusion. An attacker may obtain thousands or millions of documents, but having them does not mean knowing which ones are actually important. Artificial intelligence models can help classify files, summarize content, identify relevant terms, and locate references to specific people, projects, technologies, or contracts.
Another area of interest is programming. Artificial intelligence-based code assistants can help write, modify, review, and debug programs, as well as explain code fragments that the user does not fully understand. For a group that already has technical specialists, this capability can reduce the time required to develop certain tools and allow operators to devote more attention to other parts of the operation.
The importance of artificial intelligence does not necessarily lie in its ability to carry out an entire attack on its own. Its value may lie in accelerating numerous small tasks that, together, consume a considerable amount of time. If an operator can research, program, translate, analyze documents, and draft communications more quickly through artificial intelligence, the overall productivity of the operation increases.
RAG and the Value of Stolen Information
Among the technologies identified in Kimsuky’s environment is RAG, a system designed to combine artificial intelligence models with external information databases. Instead of relying exclusively on the knowledge that the artificial intelligence model acquired during its training, RAG makes it possible to consult specific documents and use the retrieved information to generate more contextualized responses.
In a business environment, this technology can be used to query internal databases, manuals, or large collections of documents. In an espionage context, artificial intelligence could be used to quickly analyze enormous amounts of information obtained during an intrusion. The attacker can ask questions about a document set and use artificial intelligence to locate relevant information without having to manually review each file.
This is important because the true value of espionage lies not only in obtaining data, but in turning it into knowledge. An organization can steal thousands of documents and nevertheless have difficulty determining which ones contain strategic information. An artificial intelligence tool can act as an analysis layer between the volume of stolen data and human operators.
The consequence could be a transformation of the economics of espionage. If previously it was necessary to dedicate many hours of work to reviewing documentation, automation through artificial intelligence can considerably reduce that effort. The result does not necessarily have to be a technically more sophisticated attack, but rather an attacker capable of using artificial intelligence to extract more value from each intrusion.
The Rise of Artificial Intelligence Agents
There is an important difference between a conventional chatbot and an artificial intelligence agent. While a chatbot normally responds to a specific instruction, an artificial intelligence agent can be given a broader objective and use different tools to work toward it. Depending on its configuration, the artificial intelligence can search for information, analyze results, execute certain actions, and continue with new steps.
This evolution is particularly relevant to cybersecurity because it increases the possibilities for automation through artificial intelligence. A person can use an artificial intelligence model to perform a task and then manually decide what to do, while a more autonomous system can chain together several operations. The greater the number of tools to which the artificial intelligence has access, the greater the number of actions it can potentially perform.

However, this does not mean that cyberattacks have already become completely autonomous operations. Current artificial intelligence systems still make mistakes, may misinterpret instructions, and need appropriate information to produce useful results. Humans remain essential for selecting targets, establishing priorities, evaluating results, and making strategic decisions.
The real risk may be less spectacular, but no less important for that reason. Artificial intelligence does not need to be capable of completely directing an operation to offer a significant advantage to an attacker. If artificial intelligence makes it possible to perform in one hour a task that previously required several hours, or to analyze thousands of documents instead of a few dozen, it is already changing the operational capability of whoever uses it.
North Korea and the Strategic Importance of Cyberspace
The incorporation of artificial intelligence into Kimsuky’s activities must be analyzed within the cyber strategy developed by North Korea over the last several decades. Pyongyang has built capabilities to conduct espionage operations, obtain strategic information, and attack targets related to governments, financial institutions, and companies. Cyberspace has become an especially useful tool for a country that faces significant economic and technological limitations in other areas, while artificial intelligence opens new possibilities for expanding those capabilities.
North Korean activities have also been linked to operations aimed at obtaining financial resources. Different groups linked to the country have been accused of participating in cryptocurrency thefts and other attacks against financial organizations, turning cyber capabilities into an additional source of income. This means that the same technological infrastructure can serve both intelligence objectives and operations with an economic purpose, and artificial intelligence can contribute to both types of activities.
Artificial intelligence can enhance both dimensions. An artificial intelligence tool capable of identifying sensitive information can be used for espionage, while an artificial intelligence technology capable of analyzing large amounts of data can help locate financial information. Similarly, artificial intelligence tools applied to social engineering can be used to obtain credentials, access accounts, or convince a victim to carry out certain actions.
For North Korea, the possibility of multiplying the productivity of its operators through artificial intelligence can have considerable strategic value. Artificial intelligence does not eliminate the country’s resource limitations, but it can help a small number of specialists carry out a greater amount of work. In this sense, artificial intelligence can become a tool to partially compensate for the lack of human resources.
The Challenge of Open-Source Models
Artificial intelligence models that can run locally pose a particular challenge for governments and technology companies. Their availability has enormous legitimate benefits for research, innovation, and application development, but it also allows certain users to operate without depending on external controls. Once an artificial intelligence model is installed on private infrastructure, it becomes much more difficult to monitor how it is being used.
This does not mean that open artificial intelligence models are attack tools by nature. Most have legitimate applications and can offer significant advantages to companies, universities, and developers. The problem arises when artificial intelligence is combined with specialized knowledge, stolen databases, automation tools, and other components designed to carry out malicious activities.
In addition, current artificial intelligence models are not infallible. They can produce incorrect information, generate defective code, or misinterpret an instruction, so they still require human supervision. The real capability of a group such as Kimsuky depends on the combination of technology, artificial intelligence, and operational experience, not simply on having access to a language model.
Artificial Intelligence Also Strengthens Defense
The same artificial intelligence that can increase attackers’ capabilities can also be used to defend computer systems. Companies and governments generate enormous amounts of logs, alerts, and security data, and one of their main problems is quickly determining which of those events are actually important. Artificial intelligence systems can help classify alerts, identify patterns, and detect anomalous behavior.
Artificial intelligence can also accelerate incident investigation. An artificial intelligence system can help summarize logs, analyze code, relate events occurring across different systems, and organize large amounts of information. This allows specialists to spend more time on strategic decisions and less on repetitive tasks.
The result is a technological race between attackers and defenders. As the former automate certain activities through artificial intelligence, organizations also need to automate their detection and response mechanisms. The advantage will not depend exclusively on who has access to the most powerful artificial intelligence model, but on who manages to integrate it better with their data, infrastructure, and human teams.
This race also explains why the security of artificial intelligence systems is becoming a strategic issue. A company may incorporate an artificial intelligence assistant to improve productivity, but if that system has access to sensitive information or internal tools, it can also become a new target. The protection of artificial intelligence will have to advance at the same time as its adoption.
The Threat Cannot Be Solved by Banning AI
The Kimsuky case demonstrates that there is no simple solution based solely on banning certain artificial intelligence tools. Companies can block accounts, establish limits, and detect suspicious behavior related to artificial intelligence, but attackers can switch platforms or use artificial intelligence models that operate locally. They can also combine different artificial intelligence systems to avoid depending on a single provider.
For that reason, the response must include traditional cybersecurity measures and new strategies adapted to the age of artificial intelligence. Organizations need to protect their employees’ identities, use multifactor authentication, keep their systems up to date, control permissions, and reduce the unnecessary exposure of services connected to the internet. They must also train their workers to recognize increasingly convincing social engineering attacks, including those that use artificial intelligence to generate communications.
Information protection becomes even more important in a context marked by the advancement of artificial intelligence. If attackers can use artificial intelligence to automatically analyze stolen documents, companies must reduce the amount of information that can be obtained during an intrusion and limit internal access to sensitive data. Security is no longer solely about preventing an attacker from getting in; it also involves limiting how much the attacker can exploit through artificial intelligence if they do manage to get in.

The Kimsuky case represents an important signal about the direction cyberwarfare is taking. North Korea does not need to develop a completely autonomous artificial intelligence to obtain significant advantages, as it can combine existing models with programming, document analysis, transcription, and automation tools. The true importance of this evolution lies in the ability to integrate all these artificial intelligence technologies within a coordinated operation.
Artificial intelligence is reducing the time needed to carry out many tasks that are part of a cyberattack. It can help investigate targets, process information, develop code, translate content, draft personalized messages, and analyze large amounts of documents. Each of these functions may seem limited individually, but their combination can considerably increase the productivity of a hacking group.
At the same time, it would be a mistake to think that machines have already replaced human operators. Current systems continue to make mistakes and need supervision, context, and objectives defined by people. The most immediate threat is human groups using artificial intelligence to do more quickly and on a larger scale what they already know how to do.
The same technological race is taking place on the defensive side. Governments, companies, and cybersecurity specialists use artificial intelligence to detect anomalies, investigate attacks, analyze code, and respond to incidents. Cybersecurity will have to adapt quickly to a scenario in which artificial intelligence can be both an attack tool and a defense tool. If your company needs to strengthen its cybersecurity and prepare for new threats related to artificial intelligence, you can contact ITD Consulting at [email protected] to learn about its services and technological solutions.