RismadarVoice Reporters, August 10, 2026
North Korean state-backed hackers are increasingly using artificial intelligence to enhance cyberattacks targeting military, diplomatic and academic institutions, according to a new cybersecurity report.
South Korean cybersecurity firm Genians said the Kimsuky hacking group, which is linked to North Korea’s intelligence services, had adopted AI-generated documents in a series of spear-phishing campaigns since the beginning of 2026.
The report, released on Monday, said the hackers have used AI to create malicious files disguised as legitimate documents, including research materials and invitations, to make their attacks more convincing.

According to Genians, Kimsuky has also relied on open-source artificial intelligence tools, including Ollama, GPT-4All and Msty, to operate large language models offline and reduce the likelihood of detection.
The cybersecurity firm said the use of AI represented a significant development because it allowed attackers to produce convincing decoy documents rapidly and on a much larger scale.
“AI can generate highly polished documents on a wide range of topics within a short period of time, making it a highly efficient tool for threat actors,” Genians said.
The firm added that the development showed how artificial intelligence could be used to automate and expand social engineering operations.
Kimsuky and other North Korean-linked cyber groups have been accused of conducting numerous cyber operations over the years, with some attacks reportedly focused on stealing sensitive information and generating financial gains.
British blockchain analytics company Elliptic reported that North Korean hackers stole more than $2 billion worth of cryptocurrency during the first nine months of 2025.
North Korea has also been linked by United States authorities to the 2014 cyberattack on Sony Pictures Entertainment. The incident occurred amid tensions over the release of the comedy film The Interview, which portrayed North Korean leader Kim Jong Un.
Jenny Town, a senior fellow at the Stimson Centre in Washington, said North Korea’s adoption of AI tools was consistent with the country’s long-standing use of cyber capabilities.
She noted that North Korean hackers and programmers were capable of exploiting emerging technologies to strengthen their operations, adding that the development reflected a broader trend among cybercriminals worldwide.

The report comes amid growing international concern over the potential misuse of artificial intelligence, particularly as generative AI tools become increasingly accessible.
Mark T. Hofmann, a criminal and intelligence analyst specialising in cybercrime, said AI was significantly lowering the technical barrier for individuals seeking to conduct malicious cyber operations.
He warned that threat actors around the world were likely to increasingly use generative AI and autonomous AI systems to accelerate cyberattacks.
Experts have consequently urged governments, businesses and institutions to strengthen cybersecurity measures as artificial intelligence becomes more integrated into both legitimate and malicious digital activities.


