The researchers found a broader collection of AI development software as well. That included frameworks for building AI agents, speech-to-text technology and Cursor, an AI-assisted coding tool. Taken together, Genians said the findings indicate Kimsuky may be developing ways to incorporate existing AI models more directly into its cyber operations. That could include analyzing compromised information, assisting with malware development and automating parts of an attack.
The researchers also identified decoy documents focused on finance and cryptocurrency that appeared to have been produced with AI. According to Genians, the materials were made to look like investment reports and other documents commonly encountered in professional settings. Reuters said it could not independently verify the findings.
The latest report builds on previous research from Genians showing Kimsuky using generative AI in phishing operations. In September 2025, the cybersecurity company reported that the group had used OpenAI's ChatGPT to produce a realistic fake military identification card for a campaign targeting people in South Korea.
That identification card was intended to increase the credibility of phishing emails, according to the earlier report. Malicious attachments were then used to install backdoors and remove data from targeted systems.
The newer findings suggest the group's interest in AI extends beyond producing individual pieces of deceptive content. Local model software, document-retrieval systems and agent-development frameworks could give operators a broader technical foundation for incorporating AI into different stages of their work.
Genians said North Korea's use of AI in cyber activity has expanded across areas including phishing materials, deepfakes and other social-engineering techniques.
Kimsuky has previously been linked to North Korea by government authorities. The U.S. Treasury sanctioned the group in 2023 and described it as a cyber-espionage operation controlled by the North Korean government. According to the Treasury, its intelligence gathering supported Pyongyang's strategic objectives.
U.S. and South Korean authorities, along with cybersecurity researchers, have also attributed espionage, financial theft and revenue-generating cyber activity to North Korean state-linked operations.
The Genians findings do not establish that every tool discovered was used successfully in a specific intrusion. They instead provide evidence of the software and AI capabilities being assembled around the campaign.
That distinction matters because the report points to what Kimsuky may be preparing to automate without establishing the scale or effectiveness of those efforts. What it does show is a collection of local AI, document-processing and development tools that could be incorporated into an established cyber operation.
This analysis is based on reporting from Business Standard.
Image courtesy of Unsplash.
This article was generated with AI assistance and reviewed for accuracy and quality.