Automatically translated.View original post

North Korean hacker group Kimsuky ambushes AI Stack development

North Korean hacker group Kimsuky ambushed the development of the Offline AI Stack to help Phishing and create new malware.

According to a report by The Hacker News website, a research team from Genians, a cybersecurity specialist from South Korea, has detected the operation of the Kimsuky hacker group, a group of hackers directly backed by the North Korean government, after collecting and analyzing various infrastuctures linked to the hacker group for a long period of months, to the conclusion that the hacker group has offline AI (Offline) on its own closed server, connected to various information search engines that the group possesses. As well as compiling the software parts needed to embed AI into malware.

According to the research team, as far as is known, hackers have not yet trained AI to develop a specific model of their own group, but cannot guarantee the full accuracy of this conjecture. The research team estimates that Kimsuky hackers are currently in the research and knowledge phase, a compilation of software and tools that already exists. It will lead to the development of AI to be fielded in every phase of malware generation, from the process of writing malware development to the stage of data analysis. It makes phishing deception to release malware into the victim's system more efficient. The victim's detection system is degraded by the ability to capture message smoothness. It is harder to detect, such as detecting malware behavior instead.

As for the evidence that the research team found that hackers have offline AI in the form of a large language model (LLM or Large Language Model), because such forms of AI such as Ollama, GPT4All, and Msty have been detected on the infrastructure linked to such hackers, the tools in this group have already been used or set up (Configuration), which Ollama has been detected as having created a key to activate for the first time, GPT4All has a database file named localdocs _ v3.db. It has been set up successfully. The database is a database for a LocalDocs feature called Retrieval-Augmented Generation (RAG). This feature is a feature used to process and answer questions based on data. Documents are kept private, which is important evidence that hackers tried to link their data to AI systems, but no evidence has yet been found whether they are stolen data.

In addition, the research team also detected attempts to perform AI commands to analyze data sets such as the data of the Cryptokerrency Wallet, the password data for Gmail access, and the registration data on various websites, ending "The more detailed the analysis, the better. Please do not do it haphazardly." To remind the AI to do the most detailed analysis, do not pervert the results that hackers expect.

Not only did the use of ready-made tools, the research team also detected new software development tools, such as developer libraries - LLaMaSharp, Microsoft's Semantic Kernel, and Microsoft.Agents.AI Components - for implanting AI into software written in C # and. NET has also detected OpenAI Speech-to-Text tools like Whisper and AI code-writing and editing tools like Cursor on this infrastructure, which is good evidence that this group of hackers has been using AI tools at the Stack level to insert AI into every step from upstream to downstream of the attack.

# Trending # lemon 8 diary # North Korea # kimsuky # freedomhack

9/6 Edited to

... Read moreในฐานะผู้ที่ติดตามข่าวสารเกี่ยวกับความปลอดภัยไซเบอร์มาอย่างใกล้ชิด ผมเห็นว่าการที่กลุ่มแฮกเกอร์ Kimsuky ใช้ AI Stack แบบ Offline ในการพัฒนาเครื่องมือโจมตีถือเป็นอีกก้าวหนึ่งที่สำคัญของโลกไซเบอร์ โดยเฉพาะอย่างยิ่งการผนวกเทคโนโลยี AI อย่าง Large Language Model (LLM) เข้ามาช่วยในการสร้างมัลแวร์และการโจมตีแบบ Phishing ซึ่งทำให้วิธีการโจมตีมีความซับซ้อนและมีประสิทธิภาพมากขึ้น ผมสังเกตว่า การใช้ฐานข้อมูล LocalDocs ที่มี Retrieval-Augmented Generation (RAG) ซึ่งช่วยให้ AI วิเคราะห์ข้อมูลเอกสารส่วนตัวและความลับในเครื่องมือของตนเองได้ ทำให้การโจมตีเจาะระบบหรือขโมยข้อมูลมีความแม่นยำและละเอียดมากขึ้น โดยสามารถวิเคราะห์ข้อมูลตั้งแต่รหัสผ่าน Gmail จนถึงข้อมูลคริปโตเคอร์เรนซีได้อย่างมีประสิทธิภาพ นอกจากนี้ การนำเครื่องมือพัฒนา AI อย่าง LLaMaSharp และ Semantic Kernel ที่พัฒนาโดยไมโครซอฟท์ มาใช้งานร่วมกับการเขียนโปรแกรมด้วย C# และ .NET ช่วยให้แฮกเกอร์สามารถผสมผสาน AI ลงในซอฟต์แวร์มัลแวร์ตั้งแต่ต้นน้ำถึงปลายน้ำ ที่เห็นอย่างชัดเจนคือการใช้เทคโนโลยีแปลงเสียงเป็นข้อความ (Speech-to-Text) จาก OpenAI เช่น Whisper รวมถึงเครื่องมือช่วยเขียนโค้ดอย่าง Cursor ซึ่งทั้งหมดนี้แสดงถึงความตั้งใจของกลุ่ม Kimsuky ในการสร้าง AI Stack ที่ครบวงจรเพื่อเสริมทัพไซเบอร์ให้น่าเกรงขามมากขึ้น จากประสบการณ์ส่วนตัวในการติดตามข่าวโจมตีทางไซเบอร์ ผมเห็นว่าสิ่งนี้สะท้อนให้เห็นว่าองค์กรและผู้ใช้ทั่วไปต้องตื่นตัวและเตรียมพร้อมรับมือกับภัยคุกคามที่เปลี่ยนรูปแบบเร็วขึ้นเรื่อยๆ การเสริมความรู้เรื่อง AI ในวงการไซเบอร์และการใช้เครื่องมือป้องกันที่เน้นพฤติกรรมและการวิเคราะห์ AI อย่างรอบด้าน รวมทั้งติดตามเทรนด์ต่างๆ อย่างใกล้ชิด จะช่วยลดความเสี่ยงจากการโจมตีรูปแบบใหม่ๆ ที่ซ่อนตัวอยู่ในยุค AI มากขึ้นเรื่อยๆ อย่างแน่นอน