Hackers Turn to Local AI Tools for Smarter Phishing and Cyberattacks, New Report Warns
- bysagar
- 11 Aug, 2026
AI Phishing Scam Alert: Cybercriminals are increasingly experimenting with artificial intelligence to make phishing messages, fake documents and other online attacks more convincing. A new cybersecurity report has now raised fresh concern by claiming that the North Korea-linked hacking group Kimsuky has been building a local AI setup that could help automate parts of its cyber operations.
The development does not mean hackers have created their own version of ChatGPT from scratch. Instead, researchers say the group has been using tools that allow existing large language models, or LLMs, to run locally on computers and servers without constantly relying on cloud-based AI services.
According to South Korean cybersecurity company Genians, the infrastructure linked to Kimsuky included tools such as Ollama, GPT4All and Msty. Researchers also found technology associated with document search, AI-assisted coding, speech-to-text conversion and AI agents.
The concern is that combining these capabilities could allow attackers to analyse stolen information more efficiently, create highly personalised phishing content and automate repetitive parts of a cyberattack.
What Is a Large Language Model?
A Large Language Model, commonly called an LLM, is an artificial intelligence system trained to understand and generate human-like text.
Popular AI chatbots use language models to answer questions, summarise documents, translate languages, write content and perform many other text-based tasks.
LLMs are generally built using deep-learning systems capable of identifying patterns and context in enormous amounts of text.
While these systems have many legitimate uses, the same capabilities can potentially be misused.
For example, a criminal could use generative AI to produce grammatically correct phishing emails, imitate professional business communication or quickly summarise stolen documents.
That is why cybersecurity experts are increasingly watching how malicious groups adopt AI tools.
What Did Researchers Find?
Genians said it found evidence that Kimsuky had set up software designed to operate AI models locally.
The reported tools include Ollama, GPT4All and Msty.
These applications are commonly used to download, manage or run compatible language models on local hardware.
Running an AI model locally can have an important advantage for attackers: sensitive or stolen information may be processed without uploading it to an external commercial AI service.
That could allow hackers to analyse confidential files while keeping their activity within infrastructure they control.
The researchers also identified the use of Retrieval-Augmented Generation, commonly known as RAG.
What Is RAG and Why Could Hackers Use It?
Retrieval-Augmented Generation allows an AI system to search through a collection of documents and use relevant information from those files when generating an answer.
For legitimate businesses, RAG can power internal assistants that search company manuals, research papers or large databases.
The same concept could potentially be abused by cybercriminals.
If attackers steal thousands of documents from an organisation, a locally deployed RAG system could help them rapidly search those files for valuable information.
Instead of manually reading every document, operators could potentially ask the AI to identify names, financial details, passwords, project information or other useful material.
Genians believes this type of local document-processing capability may be one reason the group is experimenting with the technology.
AI Could Make Phishing Messages Harder to Spot
Phishing traditionally relies on fake emails, text messages or websites designed to trick victims into revealing information or opening malicious files.
Older phishing attempts were often easier to identify because of spelling mistakes, unusual wording or poor grammar.
Generative AI can reduce some of those obvious warning signs.
Attackers can potentially use AI to write professional-looking messages in different languages and adjust the tone depending on the intended victim.
A scam email could imitate a company executive, HR department, bank, cryptocurrency platform or investment firm with far greater polish than many traditional mass-phishing campaigns.
The risk becomes even greater when attackers already possess personal or organisational information that allows them to personalise the message.
Researchers Also Found AI Coding Tools
The report goes beyond phishing.
Genians said infrastructure linked to the campaign contained AI-assisted development tools, including Cursor, as well as frameworks associated with AI agents.
AI coding assistants can legitimately help developers write, review and troubleshoot software more efficiently.
In a malicious context, however, these tools could potentially be used to speed up development work connected with cyber operations.
Researchers believe attackers may explore AI assistance for tasks ranging from writing scripts to analysing code and automating repetitive processes.
This does not mean AI can independently launch sophisticated attacks without human involvement, but it could reduce the amount of manual work required from operators.
Speech-to-Text Tools Also Spotted
Another notable capability identified by researchers was speech-to-text technology.
Such tools can automatically turn audio into written text.
In ordinary use, this is helpful for meetings, interviews, subtitles and accessibility.
For cyber espionage, however, attackers who obtain recorded conversations or audio files could potentially process them much faster using automated transcription.
Combined with a local language model, large quantities of transcribed information could then be searched, summarised or categorised.
This illustrates why cybersecurity researchers are paying attention not just to individual AI tools but to how several tools could be integrated into a larger workflow.
AI-Generated Finance and Crypto Documents Raise Concern
Genians also reported finding finance- and cryptocurrency-themed documents that appeared to have been generated with AI.
These files were designed to look like genuine investment reports or workplace documents.
Such material can be useful in a phishing campaign because victims are more likely to open a file if it appears polished and relevant to their work.
Once a malicious attachment is opened, attackers may attempt to install malware, steal login credentials or gain access to corporate systems.
The increasing quality of AI-generated content means users can no longer rely on poor design or bad grammar as reliable signs of a scam.
Why Local AI Is Attractive to Cybercriminals
Running AI locally offers several practical advantages.
The operator can avoid sending sensitive material to third-party servers, maintain greater control over data and customise the environment for specific tasks.
Local models can also be integrated with other software and internal document collections.
That does not automatically make local AI suspicious. Businesses, researchers and ordinary users also run AI models locally for privacy and flexibility.
The concern arises when the same technology is incorporated into infrastructure linked to known threat actors.
Genians believes the Kimsuky findings suggest that advanced cyber groups are moving from simply using public generative-AI tools toward embedding AI more deeply into their operational systems.
How Can Users Protect Themselves?
The rise of AI-generated phishing makes basic cybersecurity habits even more important.
Users should avoid trusting an email simply because it looks professional or is written in perfect English.
Always check the sender's email address carefully, especially when a message involves money, passwords, cryptocurrency, invoices or urgent requests.
Do not open unexpected attachments or click unfamiliar links without verifying the sender through another trusted channel.
Be particularly cautious when a message creates urgency, such as claiming that your account will be closed immediately or asking you to transfer money quickly.
Multi-factor authentication should also be enabled wherever possible, as it can provide an additional layer of protection if login credentials are stolen.
AI Is Changing the Cybersecurity Battle
Artificial intelligence is becoming useful to both defenders and attackers.
Cybersecurity companies already use machine learning and AI to detect unusual activity, identify malicious files and analyse threats more quickly.
At the same time, threat actors are experimenting with the technology to streamline their own operations.
The Kimsuky findings suggest that this competition could become increasingly sophisticated.
Rather than using AI only to write fake messages, advanced groups may combine local language models, document-search systems, coding assistants, speech transcription and automated agents into broader cyberattack workflows.
For ordinary users, the lesson is simple: a message, document or email that looks professional should no longer automatically be considered trustworthy.
Verification—not appearance—has become one of the most important defences against modern phishing attacks.
Disclaimer: This article is for general cybersecurity awareness. The activities described are based on findings reported by Genians and subsequent media coverage; those specific findings have not been independently verified.






