Kimsuky Expands Its Cyber Espionage Arsenal With Local AI Development Environment

Published August 13, 2026

The North Korean hacker group Kimsuky is sending fake documents to South Korean government, military, and academic workers. Opening the attached shortcut files runs hidden code that could spy on their computers.

Report priority
Medium
Targets
Windows

How it works

  • Kimsuky sends fake ZIP files with Windows shortcuts disguised as official documents.
  • Opening them runs hidden PowerShell code without the user noticing.

What to do

If you're a South Korean government, military, academic, or diplomatic worker who opened a ZIP file sent by email recently, do not open any unexpected ZIP files or shortcuts from unknown senders.

Delete suspicious emails immediately and report them to your organization's IT security team.

Technical details

Affected software: Windows

A South Korean diplomat gets an email with a ZIP file labeled 'Embassy_Confidential_2024.doc.zip'. It contains a shortcut file pretending to be a Word document. When clicked, the shortcut runs hidden PowerShell code that starts spying on the victim's computer while a fake document opens.

Kimsuky, a North Korean state-sponsored espionage group, is using Operation GitPower to target South Korean entities, including government, academia, military, and security research, with phishing campaigns that incorporate AI-assisted tools. Attackers send ZIP archives containing malicious Windows shortcut (LNK) files disguised as official documents, research materials, or embassy communications. When opened, these files execute hidden PowerShell scripts while displaying a decoy document to evade detection.

The campaign leverages local AI platforms like Ollama, GPT4All, and Msty, including GPT4All LocalDocs, to process stolen data, generate tailored lures, and automate intelligence collection. This setup enables faster adaptation of phishing content and internal analysis without relying on external cloud services, reinforcing Kimsuky's focus on persistent access and espionage rather than novel malware delivery.