Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks
- Kimsuky used local AI tools to evade monitoring and enhance operations
- Researchers observed extensive AI-driven capability building across the group’s infrastructure
- Defenders urged behavior-based detection to spot evolving AI-enabled threats
North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.
When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and terminating multiple ChatGPT accounts used in phishing and human trafficking.
That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services.
"Consistent process of capability development"
The attacks were spotted by security researchers Genianswho “conducted months of tracking and log analysis on the infrastructure utilized as C2 in...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE