Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

0
Medium
Published: 08/10/2026 (08/10/2026, 13:45:54 UTC)
Source: AlienVault OTX General

Description

The Kimsuky threat group has incorporated artificial intelligence into its attack operations, using local large language models such as Ollama, GPT4All, and Msty. Their campaign, named Operation GitPower, targets foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks involve spear phishing with malicious LNK files in ZIP archives that execute obfuscated PowerShell scripts. The group abuses Git-based repositories for command-and-control infrastructure and distributes encrypted AsyncRAT payloads disguised as image files via GitHub. Linguistic evidence links these operations to North Korean state-sponsored actors under the Reconnaissance General Bureau.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 16:33:14 UTC

Technical Analysis

Kimsuky, a North Korean state-sponsored threat actor, has integrated AI capabilities into its attack operations by establishing local large language model environments using tools like Ollama, GPT4All, and Msty. The group employs AI-generated decoy documents and retrieval-augmented generation techniques for document analysis. Their Operation GitPower campaign targets foreign diplomatic missions and critical sectors such as military, security, and virtual assets. Attack vectors include spear phishing with malicious LNK files inside ZIP archives that trigger obfuscated PowerShell scripts. They leverage Git-based repositories as command-and-control infrastructure and distribute encrypted AsyncRAT malware disguised as image files through GitHub. Linguistic markers consistent with North Korean vocabulary support attribution to the Reconnaissance General Bureau. The campaign demonstrates an evolution in threat actor tactics by integrating AI to enhance attack sophistication.

Potential Impact

The integration of AI enables Kimsuky to produce more convincing decoy documents and improve document analysis, potentially increasing the effectiveness of spear phishing and other intrusion techniques. The use of obfuscated PowerShell scripts and encrypted AsyncRAT payloads complicates detection and response efforts. Targeting diplomatic, military, security, and virtual asset sectors indicates potential espionage, data theft, and disruption risks. The abuse of legitimate platforms like GitHub for command-and-control infrastructure may evade traditional network defenses.

Defensive Guidance

No specific patch or remediation is applicable as this is an ongoing threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts involving LNK files, monitoring for obfuscated PowerShell execution, and scrutinizing unusual GitHub repository activity. Employing endpoint detection and response (EDR) solutions capable of identifying AsyncRAT and related behaviors is recommended. Awareness of the threat actor's tactics and indicators can improve incident response. Since this is a threat actor campaign, no official fix exists; mitigation relies on detection and prevention controls.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm"]
Adversary
Kimsuky
Pulse Id
6a79d612a1f9e2ac4e744aa8
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash30d5f17d5e3f85be18220a7cab0b9fff
hasha4f72ce8b5736fe3ca2083cfe21bd51697f12e900e307c357cb8523b8f86e3ec
hash22180919f562fb9f6e50d7f20b2eb3f94eb009c212b74b45cf77659fe8274d5b
hash4453b9e985f452365995c399f5292c92764570f03e6a066d7845320dd4ad09a1
hashaa9d5dd632bb90addca480eaa5ff4382
hash5746f3e78351439caebfa3721e8feea36b67263f
hash4b0358c7e4afa54bc489a6199cca132b5f4a330892eb15bf06c0c4da9e020df2
hash9be8f2be7ad882e8423c269a0540b7c73d6470311ddfcfcd318ff9d1983e2935
hashe34d73a1da492c9a79a9729f2f7d9d4b5a2448f44934bd5552bd0bbbe1586767
hash7bc61d1bbc90d66d9988fd3baacd7834b1d2dfefe6d4ac999a194bccb9ba7dfc
hash02ebc2356f9f700bbdac444cdefa0da2
hash0d8ceb7dea7d471afa2f8e753b13d2d6
hash1f378c0efc13669dada1fe340c6837bd
hash2669731cb5ff664dfb5fbfc37637876d
hash2ab3df4762fbde5d86e99a1ad147850e
hash2e76d5316663a3dc472398b1c01cb9a8
hash2eb77109cce1e8afca6245c2963e52a6
hash302725413076d1aeaee2d7f2b3692646
hash30792a0c0dfad55fb2b19d3e30e9a7d4
hash37cec428257cd41153cf43d7f1a12652
hash3b9d40f3d620ec87960b4350d42ccc03
hash3e2110d233d4543830e14c78d53900f4
hash422a221851ea6ad15f53cd3aea51c8af
hash49bdbe7e6cbb88842afcce3a9fe60e9b
hash4d87fef16790cbe1df72007d99149665
hash5577fffb5b5acd3771ef9dc696498f1e
hash5af95590a33b9bc64d95808f1fc71b78
hash5c5672bb14e1d2f07a8318ffec19b213
hash6add815cd61d6514f81a23ab8c23405a
hash73ff669fc282653bd6c42cf87ade9337
hash7f12fa589f56f6203c692715b3958d30
hash8406075af0a1e9ec09bafdc0de01f138
hash8c859a03814443c6f0da341ee594c352
hasha1c07ac866fb6b388e38c6bb1d4bbe94
hasha343d8bcf02a0554fa271452a512f3ce
hasha435292106026e257789036a70ee1a14
hasha5701848f82c65a55765dc534111899f
hashaf3fa7f22f6e97901f20326cc12bdb49
hashb406ea5b8628cb7801f47c0189b96182
hashb50dad56d891ef230656b37ce62cdada
hashb516ec6c6b37618ad65080a063270ea4
hashba0238423b5c29667cd760ccd7b000aa
hashba8e682a72c6a3e634c070f0fb057bf5
hashbbf1b0ab9fc27439de4386ed7b8fc151
hashc410055bfa198937825dfd7e41000e7a
hashc63d021de798034cbf933e1c99bcb83f
hashc7723bf166ef08ff3112257a1244f584
hashca0b57807f79f26e7f59cab2a2542da0
hashe0e4aec6d494fe68cdaa52d6878a8366
hashe22367800e9d39bc865bd50cddd0537d
hashead95793528572e7b89679860e2f2116
hashed2f8dd9b96d706d833b7aa545b8e621
hashf4e7ca8c1de252840c1f0e957cd4b717
hashf73e07efb8707e3561e9cbff74557acb
hash215343916d101c6bbe287871816e063c78103dd1
hash263efd45e5cedce553c25cf2c49dbcf28c352cd8
hash2b381a3f3e303da8832c8b60120aa6f7486264bf
hash6bd211981540cd167615e916847e383c5ddb4fbd
hash7117859ffe0380d6e5e6f9691d6d5f5fc1da20d1
hash75ea9f4a55575f39e38c1beb9ec44c0fc7b1c937
hash79fcc73e1bcb0b339336c81c8d733bf00bac4001
hash984a98b7daeee159ea018a055b86a596c5dccc46
hasha1b44d94af77705b075e67b40eb1937cedc55fa8
hashb9f25b21eccbcca77adb11a0e613d4eca4e38442
hashbeb0ab87b52a417912e0ec84cfa203fd05cae660
hashfeaad17999c1a7c768c6d841e790b2f2c006b00f
hashff6eac85bb9b11d7c1422938235896c8b3a6da3c
hash018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd
hash0432ae814945633b605c77d137bef96c7f84934c682aada69baa326dce781286
hash456ed6926b706c203ac65b5174ac2ce78a5dad2ef0f083ae1f0aedd75d811ca2
hash4d37b4ccd6e4c0c9de82e66e40dfb6412b92ea33bcf10442a290b0732eeadae0
hash5b1f75205cb79a8c8a3d8083f34b552852dfd567dd65763183b7536a29f55f5b
hasha40a61e54be9cc1671ea6832fef8139ce811a7d759058bb8b4ca86863f4cc1bd
hashb50422ec3a98d098bb3f7d728012da7e1795221c8b0624562568dff87ab5de2a

Ip

ValueDescriptionCopy
ip112.216.9.171
ip27.102.137.126
ip27.102.138.44
ip27.102.137.159

Threat ID: 6a79f49ebf8831d53900df2e

Added to database: 08/10/2026, 15:56:14 UTC

Last enriched: 08/10/2026, 16:33:14 UTC

Last updated: 08/10/2026, 16:33:14 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses