Genians found Ollama, GPT4All, and Msty (local AI tools that run on a user's own machines), plus Cursor, an AI coding assistant, on infrastructure it links to Kimsuky, a sanctioned North Korean state hacking group; the findings could not be
Genians, a South Korean cybersecurity firm, reported Monday that it had identified a fully offline AI stack on infrastructure it links to Kimsuky, a U.S.-sanctioned North Korean state-linked cyber-espionage group. The findings could not be independently verified.
Local model runners Ollama, GPT4All, and Msty let operators run large language models on their own machines, so any document or code stays inside the operator's environment. A retrieval-augmented generation (RAG) layer searches that local material. Speech-to-text software, AI agent development frameworks, and Cursor, an AI coding assistant, round out what Genians describes as a malware-development and stolen-data-analysis pipeline.
Genians' own write-up says Kimsuky has moved past AI-generated phishing lures and is now using AI as attack infrastructure. The firm also says it found finance- and cryptocurrency-themed decoy documents that appear AI-generated, designed to look like investment reports and ordinary workplace files.
The U.S. Treasury sanctioned Kimsuky in 2023 as a North Korean government-controlled cyber-espionage unit. A Reuters syndication pickup confirms the same tool list. No government or third-party researcher has publicly corroborated the new infrastructure findings, and the report leaves an open question on whether other state-linked groups have built the same offline stack.