North Korean hacking groups are building AI-powered cyberattack tools, and the results are already showing up in the wild

1 hour ago 1



North Korea’s most prolific hacking units have graduated from phishing emails and brute-force intrusions to something considerably more unsettling: building custom cyberattack tools with the help of generative AI. Multiple cybersecurity firms and government agencies have documented the shift, painting a picture of state-sponsored threat actors who are treating large language models less like novelty toys and more like weapons-grade infrastructure. The groups in question, primarily Kimsuky and APT45, have been caught using models like OpenAI’s ChatGPT and Google’s Gemini to develop malware, craft social engineering campaigns, and systematically probe software vulnerabilities at a speed that would be impossible with human labor alone. AI-generated malware with emoji comments Kaspersky reported in May 2026 that Kimsuky used a large language model to help build a malware strain called HelloDoor. The code came with a couple of telltale signatures of AI assistance: emoji-laden comments scattered throughout, and grammatical mistakes consistent with machine-generated text rather than a native developer’s work. Meanwhile, APT45 took a different approach entirely. Google Threat Intelligence ...

Read Entire Article