LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
phishing

North Korean spies are running local LLMs to cause AI mischief

Kimsuky's phishing attacks get an AI boost

zeroday.news ·

A North Korean state-sponsored cyber-espionage group, Kimsuky, is reportedly integrating artificial intelligence (AI) into its attack operations, including malware development and data analysis. According to a South Korean security firm, Genians, Kimsuky has been observed setting up and operating local large language model (LLM) environments and collecting various AI-related technologies.

Genians' investigation, which spanned several months, revealed that Kimsuky is using tools such as Ollama, GPT4All, and Msty to run LLMs locally. This approach helps prevent conversation data from being transmitted to external AI services, thereby reducing the risk of exposure for the state-sponsored actor. The group also experimented with other AI tools like Cursor and utilized retrieval-augmented generation (RAG) for local document searches, which can aid in quickly identifying valuable information within large datasets.

The researchers identified that Kimsuky has been collecting numerous libraries, including LLaMaSharp and Microsoft.Extensions.AI, as well as packages like OpenAI and Azure.AI.OpenAI. These components suggest an intent to integrate commercial AI services into their custom applications. Evidence also indicated the use of speech-to-text tools, such as OpenAI's Whisper speech recognition models, and the application of Cursor AI for code editing.

Kimsuky, operating under North Korea's Reconnaissance General Bureau, has a history of using phishing and decoy documents in attacks targeting government agencies, think tanks, academia, and security research organizations. Recent phishing campaigns by the group have involved ZIP archives containing malicious LNK files, often disguised as materials related to international events, research reports, or meeting requests.

When a recipient opens the archive and executes the LNK file, an embedded PowerShell loader is triggered. These PowerShell scripts are designed to collect extensive system information, including operating system version and architecture, system configuration, PC type, operating system installation and boot history, and a list of running processes. This information is then used to assess the infected environment and plan subsequent attacks.

The decoy documents used in these campaigns demonstrate a high level of sophistication, employing natural language, polished structures, and formats similar to actual business materials to increase user trust and induce the execution of malicious files. In some instances, AI was reportedly used to craft lures related to virtual assets and finance. The attackers also employ various obfuscation techniques, such as Base64 encoding, string splitting, and custom decoding routines, to conceal the malicious behavior of their files.

For command-and-control (C2) infrastructure, Kimsuky continues to leverage Git repositories. Genians identified multiple public GitHub repositories operated by the threat actor, some containing configuration files, PowerShell scripts, and payloads for subsequent attacks. These Git-based infrastructures were also used for malware development and testing, stolen data management, and AI technology research.

While Genians did not find evidence that Kimsuky is training its own AI models, the findings strongly suggest a continuous effort to integrate AI into existing attack capabilities. This shift necessitates that defenders move away from content-based assessment, as AI can produce highly convincing decoys, and instead focus on behavior-based detection. Organizations are advised to look for anomalous behaviors following LNK execution, such as PowerShell execution, persistence establishment, and external communications, in addition to using indicators of compromise (IoCs).

phishingai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

malware

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

What wouldst thou ask of the monkey's paw?

cloud

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

security

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.

security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.