World

North Korean hackers deploy AI to automate cyberattacks, report finds

Experts warn that artificial intelligence is lowering the barrier to entry for state-linked cybercrime, enabling large-scale social engineering against military and diplomatic targets.

Author
Adrian Cole
Political Correspondent
Published
Draft
Source: Al Jazeera Global News · original
North Korea’s hackers using AI for attacks, cybersecurity firm says
Genians says Kimsuky group has used generative tools to create malicious documents since 2026

North Korean state-backed hackers are increasingly utilising artificial intelligence to bolster cyberattacks against targets in the military, diplomacy and academia, according to a new report. Kimsuky, a hacking group linked to North Korea’s intelligence services, has employed AI-generated documents in a pattern of spear-phishing attacks since 2026, the South Korean cybersecurity firm Genians said in a report released on Monday.

The attacks involve automating the creation of malicious files disguised as legitimate documents, such as research reports and invitations, Seoul-based Genians said. To avoid detection, Kimsuky has used open-source tools such as Ollama, GPT-4All, and Msty to run large language models without an internet connection.

AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors, Genians said. This change is noteworthy because it goes beyond a shift in how decoy documents are created and demonstrates that AI can enable the automation and large-scale production of social engineering attacks.

Kimsuky and other North Korean state-linked groups have been blamed for numerous cyberattacks in recent years, many of them aimed at extracting financial gains. North Korean hackers stole cryptocurrency worth more than $2bn in the first nine months of 2025, according to a report by British blockchain analytics firm Elliptic.

Jenny Town, a senior fellow at the Stimson Center in Washington, DC, said the development was not surprising given North Korea’s history of cyberattacks. North Korea’s hackers and programmers are more than capable of utilising and exploiting various AI tools to enhance their efforts, Town told Al Jazeera. This is a new reality of all threat actors; North Korea is no exception.

The cybersecurity report comes as rapid advances in AI stoke fears about the potential for harm by bad actors and systems going rogue. US researchers last week announced that they used AI to create viruses not found in nature for the first time, raising hopes for potential advances in medical treatments but also concerns about dangers.

Mark T. Hofmann, a criminal and intelligence analyst who specialises in cybercrime, said AI had led to a seismic shift in cybercrime by lowering the bar for bad actors to carry out malicious activity. You no longer need hacking skills or a master’s degree in computer science. All you need is a computer and a motive, Hofmann told Al Jazeera. Threat actors all around the world will use more and more generative AI and, much worse, AI agents to accelerate their cyberattacks. The dark side of AI is one of the main challenges of this decade. AI-supported cyberattacks will become a regular phenomenon.

Continue reading

More from World

Read next: Damascus court sentences Assad and Najib to death for crimes against humanity
Read next: Trump Issues Mixed Signals on Iran Strategy Amidst Ongoing Regional Strikes
Read next: Turkey Parliament Approves Conditional Pardon for PKK Militants