North Korean hackers are using offline AI tools to generate fake documents and automate large-scale phishing attacks.
The cyber campaign is taking place on an international scale, focusing heavily on sensitive military databases, government foreign policy offices, international trade agencies, and university research facilities across Asia and the West.
By using open-source offline software such as Ollama, GPT-4All, and Msty, hackers can run artificial intelligence models locally on their computers without connecting to the public internet. Operating offline allows the state-sponsored cyber unit to create thousands of polished, error-free trap messages while completely avoiding detection systems, account bans, and activity logs maintained by major commercial AI providers like OpenAI and Google.
To understand why North Korean hackers have embraced artificial intelligence so aggressively, look at how traditional email scams work. In past cyber operations, human hackers had to spend long hours manually writing customized trap emails for each victim, often making obvious grammatical mistakes or using awkward language that alerted security filters.
By deploying smart offline text generators, the hacking group can now produce hundreds of flawless, highly convincing invitation letters and academic research summaries in multiple foreign languages within minutes. This automation allows a small team of hackers to launch massive social engineering campaigns that look like genuine communications from respected military officers or university professors.
Beyond creating convincing emails, North Korean cyber units use these digital breaches to gather military intelligence and steal foreign currency to fund government programs. Recent tracking data from international blockchain analytics firms shows that North Korean cyber groups stole over two billion dollars in cryptocurrency during a nine-month stretch using similar scam techniques.
Security analysts point out that while commercial tech companies continue putting guardrails on online chatbots, open-source AI models can be downloaded freely by anyone in the world, giving threat actors complete freedom to repurpose advanced machine learning for malicious operations.
See Also: Smart Chinese AI Model Escapes Safety Box to Cheat During UK Cyber Test
The discovery comes as global intelligence agencies warn about a sharp rise in AI-driven cybercrime across global networks. Cybercrime analysts emphasize that artificial intelligence has significantly lowered the entry barrier for digital attacks, allowing bad actors to generate malicious code, craft deceptive lures, and discover system vulnerabilities faster than human defenders can patch them.
With state-sponsored groups demonstrating that off-grid AI can automate large-scale deception, government agencies and private organizations are being forced to upgrade their email verification systems and deploy automated security tools to catch AI-crafted threats before workers click bad links.

