🟠 High  |  Source: The Register — Security


North Korean threat group Kimsuky is deploying locally-run large language models (LLMs) to enhance the quality and scale of their phishing campaigns, making malicious emails harder to detect through traditional means. By running AI models on-premise, the group avoids reliance on commercial AI services that have abuse controls in place. This represents a significant evolution in nation-state threat tradecraft, lowering the barrier to highly convincing, targeted spear-phishing at scale.

Security Architect’s Take: Review and harden email security controls with a focus on behavioural and contextual signals rather than relying solely on grammatical or linguistic red flags, as AI-generated phishing will appear increasingly polished. Consider deploying advanced anti-phishing tooling with AI-based detection capabilities and reinforce user awareness training to reflect the new reality that well-written, contextually plausible emails are no longer a reliable indicator of legitimacy.

Original advisory: North Korean spies are running local LLMs to cause AI mischief