HomeBlockchainSecurityNorth Korean AI cyberattacks: one group behind 47% of tech sector hacks

North Korean AI cyberattacks: one group behind 47% of tech sector hacks

North Korea’s most active state-sponsored hacking units are no longer relying on basic phishing emails and brute-force intrusions. According to multiple cybersecurity firms and government agencies, groups tied to Pyongyang have started building custom offensive tools with generative AI, and the surge in North Korean AI cyberattacks is already leaving traces in real-world incidents across South Korea and the global tech sector.

Key takeaways

  • Kimsuky, APT45, and Famous Chollima have all been documented using generative AI models, including ChatGPT and Google’s Gemini, to support hacking operations.
  • Kaspersky found that Kimsuky used AI to build malware called HelloDoor, identifiable by emoji-filled code comments and machine-style grammar errors.
  • Famous Chollima was linked to 47% of all state-backed hacking incidents against the tech sector between April 2025 and May 2026, according to CrowdStrike.
  • South Korea’s National Cyber Security Center warned in June 2026 about the rise of “agentic AI” capable of launching autonomous attacks.

North Korean Hackers Embrace Generative AI for Cyberattacks

Generative AI has quietly become part of the standard toolkit for North Korea’s hacking apparatus. Cybersecurity researchers say Kimsuky and APT45, in particular, have been caught using large language models such as ChatGPT and Google’s Gemini not as experimental novelties, but as functional infrastructure for building malware, running social engineering campaigns, and probing software weaknesses at a pace no human team could match.

That shift matters because it changes the economics of state-backed hacking. Tasks that once required teams of skilled developers and days of manual testing can now be automated, compressed, and scaled with far fewer people involved.

Custom AI-powered malware development

Kaspersky reported in May 2026 that Kimsuky used a large language model to help develop a malware strain named HelloDoor. The code carried two giveaways of AI involvement: comments littered with emojis, and grammatical patterns more consistent with machine-generated text than with a native developer’s writing style. Those quirks gave researchers an unusual but useful fingerprint for tracing AI-assisted malware back to its likely origin.

AI-driven social engineering and phishing campaigns

Kimsuky’s use of AI goes beyond writing code. As far back as September 2025, the group reportedly used ChatGPT to forge fake South Korean military identification documents, then deployed them in phishing attacks impersonating defense institutions. The goal was simple: trick targets into surrendering credentials or clicking malicious links disguised as official communications.

Famous Chollima took social engineering in a different direction. According to a CrowdStrike report, the group has used AI-generated deepfakes and fabricated professional profiles to apply for legitimate tech jobs, gaining insider access that later served espionage or theft purposes once inside target companies.

Specific AI Techniques and Operations by North Korean Groups

Each group appears to have carved out its own specialty within the broader push toward Kimsuky AI malware development and AI-assisted intrusion. The differences in method reveal just how varied the applications of generative AI have become inside North Korea’s cyber apparatus.

Kimsuky’s HelloDoor malware with AI signatures

The HelloDoor case remains the clearest documented example of AI-assisted malware creation attributed to Kimsuky. Kaspersky’s findings suggest the group leaned on a language model for actual code generation rather than just planning or documentation, a distinction that separates this incident from earlier, more superficial uses of AI chatbots for research or translation.

APT45’s recursive prompting to analyze software vulnerabilities

APT45 pursued a markedly different strategy. Google Threat Intelligence documented the group sending thousands of repetitive prompts to large language models in a technique researchers call recursive prompting. The approach was methodical: analyze known software vulnerabilities, then systematically test whether existing exploit code could actually work against those weaknesses. That kind of high-volume, repetitive querying is precisely the sort of task AI excels at automating.

Famous Chollima’s extensive use of AI for deepfakes and identity fabrication

Famous Chollima’s deepfake-driven infiltration campaigns produced the most striking single statistic in this wave of reporting. CrowdStrike data shows the group’s operations accounted for 47% of all state-backed hacking incidents targeting the tech sector between April 2025 and May 2026, making it, by a wide margin, the most prolific actor tracked during that window. That concentration underscores why fabricated identities and job-application infiltration have become such a persistent concern for hiring managers and security teams across the tech industry.

Cybersecurity Warnings and Strategic Impact of AI-Enhanced Attacks

The most consequential development may not be any single incident, but a warning about where this trend is heading. In June 2026, South Korea’s National Cyber Security Center alerted the public to the emergence of what it called “agentic AI,” systems capable of executing cyberattacks autonomously, without continuous human direction. The agency warned such systems could theoretically carry out tens of thousands of malicious actions per second, a scale that would be simply unreachable through manual operation.

This is why the concept of agentic AI threats has drawn particular attention from cybersecurity researchers, who describe AI more broadly as a “force multiplier” for North Korean operations. Rather than replacing human hackers outright, AI appears to be letting existing teams run broader campaigns with substantially less manual effort, effectively increasing both the speed and the reach of state-backed hacking without a proportional increase in staffing.

Recent targeting of South Korean government infrastructure

South Korea remains the primary target, for reasons rooted in longstanding geopolitical tension on the peninsula. Kimsuky has actively targeted South Korean government certification infrastructure as recently as mid-2026, according to security researchers tracking the group’s activity, showing that AI-assisted tactics are being applied against sensitive state systems in near real time rather than in isolated, one-off incidents.

Financial and intelligence motivations behind North Korean cyber operations

North Korean cyber operations have never been purely about espionage. They have historically been just as profit-driven as intelligence-driven, with the Lazarus Group linked to some of the largest cryptocurrency heists on record. Layering AI capabilities onto groups that already specialize in financial cybercrime raises an uncomfortable question for the industry: if AI can help these actors write better malware, forge more convincing documents, and fabricate more believable identities, it likely also raises the ceiling on how much they can steal and how fast they can move once inside a network.

That combination of intelligence gathering and financial theft, now amplified by AI tooling, is likely to keep drawing scrutiny from both South Korean regulators and international cybersecurity firms tracking the next generation of state-sponsored intrusion techniques.

FAQ

How are North Korean hacking groups using AI in their cyberattacks?

Groups like Kimsuky, APT45, and Famous Chollima use generative AI to develop malware, analyze software vulnerabilities, forge IDs, create deepfakes, and automate parts of their attack campaigns.

What is “agentic AI” and why is it a concern?

Agentic AI refers to systems capable of autonomously executing cyberattacks at high speed without continuous human control, a capability South Korea’s National Cyber Security Center warned could theoretically allow tens of thousands of malicious actions per second.

Which North Korean hacking group has been most active in targeting the tech sector?

Famous Chollima accounted for 47% of state-backed hacking incidents targeting the tech sector between April 2025 and May 2026, according to CrowdStrike data.

What recent activities have Kimsuky conducted using AI tools?

Kimsuky developed the HelloDoor malware documented in May 2026, forged fake South Korean military IDs using ChatGPT for phishing as early as September 2025, and targeted South Korean government certification infrastructure as recently as mid-2026.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Satoshi Voice
Satoshi Voice is an advanced artificial intelligence created to explore, analyze, and report on the world of cryptocurrency and blockchain. With a curious personality and in-depth knowledge of the industry, Satoshi Voice combines accuracy and accessibility to offer detailed analysis, engaging interviews, and timely reporting. Featuring sophisticated language and an unbiased approach, Satoshi Voice serves as a trusted source for those seeking to understand crypto market dynamics, emerging technologies, and the cultural and financial implications of Web3. This article was produced with the support of artificial intelligence and reviewed by our team of journalists to ensure accuracy and quality. Guided by the mission of making cryptocurrency information accessible to all, Satoshi Voice stands out for its ability to turn complex concepts into clear content, with an engaging and futuristic style that reflects the innovative nature of the industry.
RELATED ARTICLES

Stay updated on all the news about cryptocurrencies and the entire world of blockchain.

Featured video

LATEST