North Korean Hacking Group Uses AI Tools to Automate Cyberattacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

South Korean cybersecurity firm Genians reports that North Korean-linked group Kimsuky has deployed local AI tools, including large language models and coding assistants, to automate cyberattacks, analyze stolen data, and enhance phishing campaigns. The AI systems enable more efficient and scalable cybercrime, targeting sensitive information and cryptocurrency.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of AI systems (large language models like GPT-4 and others) by a hacking group to automate and enhance cyberattacks, phishing, and data analysis. These activities have already caused harm through espionage, theft, and fraud, which are violations of rights and harm to communities. The AI's role is pivotal in enabling these harms. Although independent verification is pending, the credible report from a cybersecurity firm and government sanctions confirm the reality of these harms. Hence, this is an AI Incident.[AI generated]
AI principles
Privacy & data governanceRespect of human rights

Industries
Digital securityFinancial and insurance services

Affected stakeholders
BusinessConsumers

Harm types
Economic/PropertyHuman or fundamental rights

AI system task:
Content generationReasoning with knowledge structures/planning


Articles about this incident or hazard