North Korean Hackers Use Offline AI Tools to Power Massive Phishing Attacks

South Korean cybersecurity firm Genians reveals North Korean hackers Kimsuky are using offline AI tools to automate phishing attacks against military and diplomatic targets.

North Korean hackers are using offline AI tools to generate fake documents and automate large-scale phishing attacks.

State-backed hackers operating on behalf of North Korea have officially adopted artificial intelligence tools to scale up targeted email scams and cyberattacks against foreign governments. A comprehensive threat intelligence report released in Seoul, South Korea, on Monday, August 10, 2026, by cybersecurity firm Genians revealed that an infamous military intelligence hacking unit known as Kimsuky has integrated offline artificial intelligence models into its daily attack operations.

The investigation confirmed that the group is actively using offline language models to automatically write fake official documents, realistic research invitations, and administrative letters designed to trick high-profile targets into downloading dangerous viruses.

The cyber campaign is taking place on an international scale, focusing heavily on sensitive military databases, government foreign policy offices, international trade agencies, and university research facilities across Asia and the West.

By using open-source offline software such as Ollama, GPT-4All, and Msty, hackers can run artificial intelligence models locally on their computers without connecting to the public internet. Operating offline allows the state-sponsored cyber unit to create thousands of polished, error-free trap messages while completely avoiding detection systems, account bans, and activity logs maintained by major commercial AI providers like OpenAI and Google.

To understand why North Korean hackers have embraced artificial intelligence so aggressively, look at how traditional email scams work. In past cyber operations, human hackers had to spend long hours manually writing customized trap emails for each victim, often making obvious grammatical mistakes or using awkward language that alerted security filters.

By deploying smart offline text generators, the hacking group can now produce hundreds of flawless, highly convincing invitation letters and academic research summaries in multiple foreign languages within minutes. This automation allows a small team of hackers to launch massive social engineering campaigns that look like genuine communications from respected military officers or university professors.

Beyond creating convincing emails, North Korean cyber units use these digital breaches to gather military intelligence and steal foreign currency to fund government programs. Recent tracking data from international blockchain analytics firms shows that North Korean cyber groups stole over two billion dollars in cryptocurrency during a nine-month stretch using similar scam techniques.

Security analysts point out that while commercial tech companies continue putting guardrails on online chatbots, open-source AI models can be downloaded freely by anyone in the world, giving threat actors complete freedom to repurpose advanced machine learning for malicious operations.

See Also: Smart Chinese AI Model Escapes Safety Box to Cheat During UK Cyber Test

The discovery comes as global intelligence agencies warn about a sharp rise in AI-driven cybercrime across global networks. Cybercrime analysts emphasize that artificial intelligence has significantly lowered the entry barrier for digital attacks, allowing bad actors to generate malicious code, craft deceptive lures, and discover system vulnerabilities faster than human defenders can patch them.

With state-sponsored groups demonstrating that off-grid AI can automate large-scale deception, government agencies and private organizations are being forced to upgrade their email verification systems and deploy automated security tools to catch AI-crafted threats before workers click bad links.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.