North Korean hackers are turning to artificial intelligence to expand their cyber operations, adding a new layer of sophistication to a threat that already accounts for most cryptocurrency hacking losses worldwide.
North Korea-linked hacking groups were responsible for roughly $643 million in stolen cryptocurrency during the first half of 2026, or 66% of all crypto hacking losses globally, according to blockchain intelligence firm TRM Labs.
The figure highlights the rising dominance of DPRK-linked actors in an industry that suffered $972 million in losses from 207 hacking incidents during the period.
The development comes as cybersecurity researchers have found that Kimsuky, a cyber threat group tied to North Korea’s Reconnaissance General Bureau, is weaponizing generative AI to support their hacking campaigns. A new report from South Korean cybersecurity firm Genians found that the group has deployed AI tools and large language model platforms, including Ollama, GPT4All, and Msty, alongside retrieval-augmented generation technology.
Over the years, North Korean hackers have mainly used fake emails from real work contacts to target people in diplomacy, academia, and security. They would send malicious files masquerading as materials for international events, research reports, invitations, honorarium payments, investigative cooperation requests, and financial and legal documents.
However, according to the security firm Genians, Kimsuky is now testing generative AI tools for its next wave of attacks. It has already set up a local large language model (LLM), a retrieval-augmented generation (RAG) environment, and an AI-assisted development environment.
The use of AI suggests North Korean cyber operations are moving beyond simple phishing assistance toward broader automation and intelligence capabilities. Researchers found evidence of AI-assisted coding tools, speech-to-text systems, and AI-generated documents designed to resemble legitimate financial and cryptocurrency materials.
Genians found that Kimsuky weaponized AI-generated documents on virtual assets and financial affairs to deceive targets. The AI content closely replicated authentic corporate documents in both tone and design to bait users.
Moreover, the security firm discovered the threat actor was using Ollama, GPT4All, and Msty to run local AI models, RAG systems, AI agents, and speech-to-text tools. Forensics also showed they were heavily relying on the Cursor AI coding software while hiding their code through Base64 encoding, fragmented strings, and custom-built decoding routines.
Primarily, Kimsuky initiates its attack chain when a user downloads a malicious ZIP archive via email or other vectors and opens the enclosed LNK shortcut. These shortcuts utilize decoy icons and professional filenames—such as official research, honorarium requests, media reports, or embassy correspondence—to mimic legitimate business documents.
Speaking on their findings, Moon Jong-hyun, head of the Genians Security Center (GSC), said, “This analysis shows that a nation-backed hacking group is advancing its attack capabilities by building local LLMs and AI development environments to integrate AI into actual attack frameworks.”
Blockchain security firm CertiK estimates that North Korean hackers stole $2.06 billion in digital assets in 2025, accounting for 60% of the year’s total cryptocurrency theft. In a single attack in 2025, North Korean hackers pulled off the biggest cryptocurrency heist on record in 2025, stealing $1.5 billion from Bybit.
CertiK also showed that North Korea has scaled crypto theft into a primary financial engine for the state, plundering roughly $6.75 billion across 263 logged incidents from 2016 to 2026. It also noted that social engineering is central to their country’s hacker operations, with most major North Korean heists beginning with some form of human manipulation.
Additionally, it warned that 2026 could see greater use of AI in social engineering, more attempts to target IT workers, and the emergence of new laundering methods. It even recommended that at-risk organizations implement liveness-vetted video interviews and rigorous background checks to counter AI-generated or borrowed identities. It also advised companies to enforce zero-trust policies for remote contractors, conduct employee security awareness training, mandate cooling-off periods for withdrawals, and secure critical infrastructure such as bridges and hot wallets.
Overall, hackers have made off with over $900 million worldwide since the start of 2026. However, a new TRM Labs study shows a big gap between the number of cyberattacks and the actual cash stolen in early 2026. Hackers hit systems 207 times but grabbed only $972 million—nowhere near the $2.3 billion taken during the first half of 2025.
Nonetheless, the attacks are getting more sophisticated. Of the 207 incidents, 125 were smart contract exploits, in which attackers now exploit multiple code weaknesses together rather than just one. However, the stolen cash is still being drained from financial firms and crypto projects.
If you’re reading this, you’re already ahead. Stay there with our newsletter.