Integrating AI into attack operations, from AI-generated decoy documents to a local LLM
The North Korean hacker group Kimsuky is using AI tools like Ollama and GPT4All to create fake documents and automate attacks on foreign governments, military, and security firms. They hide malware in ZIP files and GitHub image files to steal data and spy on targets.
- Report priority
- High
- Targets
- Threat actor: Kimsuky+2 more
How it works
- Kimsuky sends ZIP files with malicious LNK shortcuts.
- These run hidden PowerShell scripts that connect to GitHub repositories to download more malware.
- The group also uses AI tools like Ollama and GPT4All to generate fake documents and analyze stolen files.
- Attackers disguise malware as image files and use encrypted AsyncRAT to spy on targets.
- Linguistic clues link the group to North Korea's Reconnaissance General Bureau.
What to do
If you work for a government agency, military, or security firm and received suspicious ZIP files or GitHub-linked image files, check for unexpected LNK shortcuts or PowerShell scripts running in your email attachments. If you use GitHub for work, monitor for unusual repository activity or encrypted files you didn't upload.
Delete any suspicious ZIP files or GitHub-linked image files immediately. Scan your system for malware using a trusted antivirus. Report any unusual activity to your IT security team or cybersecurity contact. Enable email filtering to block unknown senders and monitor GitHub accounts for unauthorized access. If you suspect an attack, contact your organization's cybersecurity incident response team for further investigation.
Technical details
Affected software: Threat actor: Kimsuky, Government, Defense
Kimsuky sent a fake diplomatic memo via email. The attachment was a ZIP file containing a malicious LNK shortcut. When opened, it ran a PowerShell script that downloaded an AsyncRAT from a GitHub repository. The AI-generated document tricked a government employee into opening it, letting the attackers spy on their network.
The Kimsuky threat group, linked to North Korea's Reconnaissance General Bureau, has integrated AI tools into its attack chain under Operation GitPower. They deploy local AI environments using Ollama, GPT4All, and Msty to generate decoy documents and analyze targets via retrieval-augmented generation. Attacks target diplomatic, military, security, and virtual asset sectors through malicious LNK files in ZIP archives, which execute obfuscated PowerShell scripts.
These scripts abuse Git repositories for command-and-control, while encrypted AsyncRAT payloads, disguised as image files, are distributed via GitHub. Linguistic patterns in attack materials (e.g., North Korean terms like "site" or "join history") reinforce state-sponsored attribution.