Skip to main content

Tag: kimsuky

4 articles

Cluttered server room with computer equipment, cables, and monitors, plus AI development hardware and software tools.

North Korean Spies Deploy Local AI Tools to Bolster Cyber Operations

North Korean spies are taking their cyber operations to the next level by deploying local AI tools, marking a significant shift from experimentation to integration. This development enables them to enhance malware development, data analysis, and attack techniques, posing a more sophisticated threat.

Analyst 207
A cluttered server room with rows of computer servers and networking equipment, highlighting a single organized server.

Kimsuky Bolsters Phishing Arsenal with Offline AI Infrastructure

North Korean hackers Kimsuky are taking phishing to the next level by leveraging offline AI infrastructure, a deliberate move to supercharge their espionage capabilities. Genians, a South Korean security firm, uncovered evidence of language-model tools like Ollama and GPT4All being installed and run on Kimsuky's servers.

Analyst 207
Laptop screen on cluttered office desk with subtle hint of fake installation page.

Kimsuky Expands Malware Arsenal with HTTPSpy, HelloDoor

Kimsuky, a notorious North Korean hacking group, has upgraded its malware arsenal with HTTPSpy and HelloDoor, using clever tactics like fake installation pages and a spoofed Webex meeting to infiltrate targets. The group's latest attacks involve highly tailored social engineering and real-time infection verification to maximize success.

Analyst 207
Cluttered office desk with laptop and scattered papers near a bright window.

Kimsuky APT Expands Arsenal with Advanced PebbleDash Malware Tools

Kimsuky's malware arsenal just got a major boost with the addition of advanced PebbleDash tools, allowing the group to infiltrate systems with even more sophisticated tactics. Their latest campaign uses clever spear-phishing and malicious attachments to catch victims off guard.

Analyst 207