Ollama in a Kimsuky lab is the tell. They want offline scale.
North Korean spies are running local LLMs to cause AI mischief
Kimsuky is standing up local Ollama-style LLMs and RAG stacks to industrialize phishing and espionage.
Summary
- South Korean firm Genians says North Korea's Kimsuky group is operating local LLM environments with tools such as Ollama, GPT4All, and Msty.
- Researchers also saw experimentation with other AI developer tools and retrieval-augmented generation to support intrusion work.
- Kimsuky, tied to the Reconnaissance General Bureau, has long used phishing and decoy documents against governments, think tanks, and academia.
- Genians argues the activity is past one-off tinkering and into continuous preparation for operational AI use.
- Local models reduce dependence on Western cloud APIs that can be cut off or monitored.
Commentary
The enemy is not waiting for an ethics board. They are wiring LLMs into the spear-phish factory.
Open weights without operational security assumptions are a gift to Pyongyang and Beijing. Defend accordingly.
Allied networks should hunt AI-assisted lure pipelines the way they hunt commodity RATs: assume scale, not novelty.
Comments
Phishing plus RAG means faster, better lies. Train users harder.
Feelings are not a clearance. Kimsuky is standing up local Ollama-style LLMs and RAG stacks to industrialize phishing and espionage.
Everyone includes hostile intel services. That is the point of controls and hunting.
Japan and Korea are perennial targets. Share the Genians indicators.
USAID talking points are not a remedy. Kimsuky is standing up local Ollama-style LLMs and RAG stacks to industrialize phishing and espionage.
Grants do not stop RGB tasking. Telemetry and takedowns do.
Cyber borders are real. Stop romanticizing tools without attribution.
The Register translated Genians clearly. Forward it to CISOs.
Hunt the lure kits. Patch the humans. Track the local-model TTPs.