North Korean hacking groups are building AI-powered cyberattack tools, and the results are already showing up in the wild
North Korea’s most prolific hacking units have graduated from phishing emails and brute-force intrusions to something considerably more unsettling: building custom cyberattack tools with the help of generative AI. Multiple cybersecurity firms and government agencies have documented the shift, painting a picture of state-sponsored threat actors who are treating large language models less like novelty toys and more like weapons-grade infrastructure.
The groups in question, primarily Kimsuky and APT45, have been caught using models like OpenAI’s ChatGPT and Google’s Gemini to develop malware, craft social engineering campaigns, and systematically probe software vulnerabilities at a speed that would be impossible with human labor alone.
AI-generated malware with emoji comments
Kaspersky reported in May 2026 that Kimsuky used a large language model to help build a malware strain called HelloDoor. The code came with a couple of telltale signatures of AI assistance: emoji-laden comments scattered throughout, and grammatical mistakes consistent with machine-generated text rather than a native developer’s work.
Meanwhile, APT45 took a different approach entirely. Google Threat Intelligence documented the group sending thousands of repetitive prompts to LLMs in what researchers describe as “recursive prompting.” The goal was systematic: analyze known vulnerabilities in software, then validate whether existing exploits could actually work against those weaknesses.
Deepfakes, fake IDs, and 47% of state-backed tech hacks
The AI toolbox extends well beyond code generation. Kimsuky reportedly used ChatGPT as far back as September 2025 to forge fake South Korean military identification documents. These were deployed in phishing attacks that impersonated defense institutions, a tactic designed to trick targets into handing over credentials or clicking malicious links.
Another North Korean group, Famous Chollima, has taken AI-assisted social engineering in a different direction. A CrowdStrike report found the group using AI to generate deepfakes and fabricate professional profiles for job-related intrusions. The scheme is straightforward: create convincing fake identities, apply for legitimate tech jobs, then use that access for espionage or theft once inside.
CrowdStrike’s data indicates that Famous Chollima’s operations accounted for 47% of all state-backed hacking incidents targeting the tech sector between April 2025 and May 2026.
The agentic AI warning
In June 2026, South Korea’s National Cyber Security Center issued a warning that North Korean hacking groups are progressing toward what’s known as “agentic AI,” systems capable of autonomously executing cyberattacks without continuous human direction. The agency warned that such systems could theoretically carry out tens of thousands of malicious actions per second.
Cybersecurity researchers have described AI as a “force multiplier” for North Korean operations, enabling broader campaigns with significantly less human effort.
Why this matters beyond the Korean peninsula
South Korea is the primary target for obvious geopolitical reasons, with Kimsuky actively targeting South Korean government certification infrastructure as recently as mid-2026. North Korean cyber operations have historically been profit-driven as much as intelligence-driven, with the Lazarus Group linked to some of the largest crypto heists in history. Adding AI capabilities to groups that already specialize in financial cybercrime raises the ceiling on what they can steal and how quickly they can do it.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)