Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
The Kimsuky threat group has incorporated artificial intelligence into its attack operations, using local large language models such as Ollama, GPT4All, and Msty. Their campaign, named Operation GitPower, targets foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks involve spear phishing with malicious LNK files in ZIP archives that execute obfuscated PowerShell scripts. The group abuses Git-based repositories for command-and-control infrastructure and distributes encrypted AsyncRAT payloads disguised as image files via GitHub. Linguistic evidence links these operations to North Korean state-sponsored actors under the Reconnaissance General Bureau.
AI Analysis
Technical Summary
Kimsuky, a North Korean state-sponsored threat actor, has integrated AI capabilities into its attack operations by establishing local large language model environments using tools like Ollama, GPT4All, and Msty. The group employs AI-generated decoy documents and retrieval-augmented generation techniques for document analysis. Their Operation GitPower campaign targets foreign diplomatic missions and critical sectors such as military, security, and virtual assets. Attack vectors include spear phishing with malicious LNK files inside ZIP archives that trigger obfuscated PowerShell scripts. They leverage Git-based repositories as command-and-control infrastructure and distribute encrypted AsyncRAT malware disguised as image files through GitHub. Linguistic markers consistent with North Korean vocabulary support attribution to the Reconnaissance General Bureau. The campaign demonstrates an evolution in threat actor tactics by integrating AI to enhance attack sophistication.
Potential Impact
The integration of AI enables Kimsuky to produce more convincing decoy documents and improve document analysis, potentially increasing the effectiveness of spear phishing and other intrusion techniques. The use of obfuscated PowerShell scripts and encrypted AsyncRAT payloads complicates detection and response efforts. Targeting diplomatic, military, security, and virtual asset sectors indicates potential espionage, data theft, and disruption risks. The abuse of legitimate platforms like GitHub for command-and-control infrastructure may evade traditional network defenses.
Mitigation Recommendations
No specific patch or remediation is applicable as this is an ongoing threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts involving LNK files, monitoring for obfuscated PowerShell execution, and scrutinizing unusual GitHub repository activity. Employing endpoint detection and response (EDR) solutions capable of identifying AsyncRAT and related behaviors is recommended. Awareness of the threat actor's tactics and indicators can improve incident response. Since this is a threat actor campaign, no official fix exists; mitigation relies on detection and prevention controls.
Indicators of Compromise
- hash: 30d5f17d5e3f85be18220a7cab0b9fff
- hash: a4f72ce8b5736fe3ca2083cfe21bd51697f12e900e307c357cb8523b8f86e3ec
- ip: 112.216.9.171
- ip: 27.102.137.126
- hash: 22180919f562fb9f6e50d7f20b2eb3f94eb009c212b74b45cf77659fe8274d5b
- hash: 4453b9e985f452365995c399f5292c92764570f03e6a066d7845320dd4ad09a1
- hash: aa9d5dd632bb90addca480eaa5ff4382
- hash: 5746f3e78351439caebfa3721e8feea36b67263f
- hash: 4b0358c7e4afa54bc489a6199cca132b5f4a330892eb15bf06c0c4da9e020df2
- hash: 9be8f2be7ad882e8423c269a0540b7c73d6470311ddfcfcd318ff9d1983e2935
- ip: 27.102.138.44
- hash: e34d73a1da492c9a79a9729f2f7d9d4b5a2448f44934bd5552bd0bbbe1586767
- hash: 7bc61d1bbc90d66d9988fd3baacd7834b1d2dfefe6d4ac999a194bccb9ba7dfc
- hash: 02ebc2356f9f700bbdac444cdefa0da2
- hash: 0d8ceb7dea7d471afa2f8e753b13d2d6
- hash: 1f378c0efc13669dada1fe340c6837bd
- hash: 2669731cb5ff664dfb5fbfc37637876d
- hash: 2ab3df4762fbde5d86e99a1ad147850e
- hash: 2e76d5316663a3dc472398b1c01cb9a8
- hash: 2eb77109cce1e8afca6245c2963e52a6
- hash: 302725413076d1aeaee2d7f2b3692646
- hash: 30792a0c0dfad55fb2b19d3e30e9a7d4
- hash: 37cec428257cd41153cf43d7f1a12652
- hash: 3b9d40f3d620ec87960b4350d42ccc03
- hash: 3e2110d233d4543830e14c78d53900f4
- hash: 422a221851ea6ad15f53cd3aea51c8af
- hash: 49bdbe7e6cbb88842afcce3a9fe60e9b
- hash: 4d87fef16790cbe1df72007d99149665
- hash: 5577fffb5b5acd3771ef9dc696498f1e
- hash: 5af95590a33b9bc64d95808f1fc71b78
- hash: 5c5672bb14e1d2f07a8318ffec19b213
- hash: 6add815cd61d6514f81a23ab8c23405a
- hash: 73ff669fc282653bd6c42cf87ade9337
- hash: 7f12fa589f56f6203c692715b3958d30
- hash: 8406075af0a1e9ec09bafdc0de01f138
- hash: 8c859a03814443c6f0da341ee594c352
- hash: a1c07ac866fb6b388e38c6bb1d4bbe94
- hash: a343d8bcf02a0554fa271452a512f3ce
- hash: a435292106026e257789036a70ee1a14
- hash: a5701848f82c65a55765dc534111899f
- hash: af3fa7f22f6e97901f20326cc12bdb49
- hash: b406ea5b8628cb7801f47c0189b96182
- hash: b50dad56d891ef230656b37ce62cdada
- hash: b516ec6c6b37618ad65080a063270ea4
- hash: ba0238423b5c29667cd760ccd7b000aa
- hash: ba8e682a72c6a3e634c070f0fb057bf5
- hash: bbf1b0ab9fc27439de4386ed7b8fc151
- hash: c410055bfa198937825dfd7e41000e7a
- hash: c63d021de798034cbf933e1c99bcb83f
- hash: c7723bf166ef08ff3112257a1244f584
- hash: ca0b57807f79f26e7f59cab2a2542da0
- hash: e0e4aec6d494fe68cdaa52d6878a8366
- hash: e22367800e9d39bc865bd50cddd0537d
- hash: ead95793528572e7b89679860e2f2116
- hash: ed2f8dd9b96d706d833b7aa545b8e621
- hash: f4e7ca8c1de252840c1f0e957cd4b717
- hash: f73e07efb8707e3561e9cbff74557acb
- ip: 27.102.137.159
- hash: 215343916d101c6bbe287871816e063c78103dd1
- hash: 263efd45e5cedce553c25cf2c49dbcf28c352cd8
- hash: 2b381a3f3e303da8832c8b60120aa6f7486264bf
- hash: 6bd211981540cd167615e916847e383c5ddb4fbd
- hash: 7117859ffe0380d6e5e6f9691d6d5f5fc1da20d1
- hash: 75ea9f4a55575f39e38c1beb9ec44c0fc7b1c937
- hash: 79fcc73e1bcb0b339336c81c8d733bf00bac4001
- hash: 984a98b7daeee159ea018a055b86a596c5dccc46
- hash: a1b44d94af77705b075e67b40eb1937cedc55fa8
- hash: b9f25b21eccbcca77adb11a0e613d4eca4e38442
- hash: beb0ab87b52a417912e0ec84cfa203fd05cae660
- hash: feaad17999c1a7c768c6d841e790b2f2c006b00f
- hash: ff6eac85bb9b11d7c1422938235896c8b3a6da3c
- hash: 018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd
- hash: 0432ae814945633b605c77d137bef96c7f84934c682aada69baa326dce781286
- hash: 456ed6926b706c203ac65b5174ac2ce78a5dad2ef0f083ae1f0aedd75d811ca2
- hash: 4d37b4ccd6e4c0c9de82e66e40dfb6412b92ea33bcf10442a290b0732eeadae0
- hash: 5b1f75205cb79a8c8a3d8083f34b552852dfd567dd65763183b7536a29f55f5b
- hash: a40a61e54be9cc1671ea6832fef8139ce811a7d759058bb8b4ca86863f4cc1bd
- hash: b50422ec3a98d098bb3f7d728012da7e1795221c8b0624562568dff87ab5de2a
Integrating AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
Description
The Kimsuky threat group has incorporated artificial intelligence into its attack operations, using local large language models such as Ollama, GPT4All, and Msty. Their campaign, named Operation GitPower, targets foreign diplomatic missions and sectors including military, security, and virtual assets. Attacks involve spear phishing with malicious LNK files in ZIP archives that execute obfuscated PowerShell scripts. The group abuses Git-based repositories for command-and-control infrastructure and distributes encrypted AsyncRAT payloads disguised as image files via GitHub. Linguistic evidence links these operations to North Korean state-sponsored actors under the Reconnaissance General Bureau.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Kimsuky, a North Korean state-sponsored threat actor, has integrated AI capabilities into its attack operations by establishing local large language model environments using tools like Ollama, GPT4All, and Msty. The group employs AI-generated decoy documents and retrieval-augmented generation techniques for document analysis. Their Operation GitPower campaign targets foreign diplomatic missions and critical sectors such as military, security, and virtual assets. Attack vectors include spear phishing with malicious LNK files inside ZIP archives that trigger obfuscated PowerShell scripts. They leverage Git-based repositories as command-and-control infrastructure and distribute encrypted AsyncRAT malware disguised as image files through GitHub. Linguistic markers consistent with North Korean vocabulary support attribution to the Reconnaissance General Bureau. The campaign demonstrates an evolution in threat actor tactics by integrating AI to enhance attack sophistication.
Potential Impact
The integration of AI enables Kimsuky to produce more convincing decoy documents and improve document analysis, potentially increasing the effectiveness of spear phishing and other intrusion techniques. The use of obfuscated PowerShell scripts and encrypted AsyncRAT payloads complicates detection and response efforts. Targeting diplomatic, military, security, and virtual asset sectors indicates potential espionage, data theft, and disruption risks. The abuse of legitimate platforms like GitHub for command-and-control infrastructure may evade traditional network defenses.
Defensive Guidance
No specific patch or remediation is applicable as this is an ongoing threat actor campaign rather than a software vulnerability. Defenders should focus on detecting and blocking spear phishing attempts involving LNK files, monitoring for obfuscated PowerShell execution, and scrutinizing unusual GitHub repository activity. Employing endpoint detection and response (EDR) solutions capable of identifying AsyncRAT and related behaviors is recommended. Awareness of the threat actor's tactics and indicators can improve incident response. Since this is a threat actor campaign, no official fix exists; mitigation relies on detection and prevention controls.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm"]
- Adversary
- Kimsuky
- Pulse Id
- 6a79d612a1f9e2ac4e744aa8
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash30d5f17d5e3f85be18220a7cab0b9fff | — | |
hasha4f72ce8b5736fe3ca2083cfe21bd51697f12e900e307c357cb8523b8f86e3ec | — | |
hash22180919f562fb9f6e50d7f20b2eb3f94eb009c212b74b45cf77659fe8274d5b | — | |
hash4453b9e985f452365995c399f5292c92764570f03e6a066d7845320dd4ad09a1 | — | |
hashaa9d5dd632bb90addca480eaa5ff4382 | — | |
hash5746f3e78351439caebfa3721e8feea36b67263f | — | |
hash4b0358c7e4afa54bc489a6199cca132b5f4a330892eb15bf06c0c4da9e020df2 | — | |
hash9be8f2be7ad882e8423c269a0540b7c73d6470311ddfcfcd318ff9d1983e2935 | — | |
hashe34d73a1da492c9a79a9729f2f7d9d4b5a2448f44934bd5552bd0bbbe1586767 | — | |
hash7bc61d1bbc90d66d9988fd3baacd7834b1d2dfefe6d4ac999a194bccb9ba7dfc | — | |
hash02ebc2356f9f700bbdac444cdefa0da2 | — | |
hash0d8ceb7dea7d471afa2f8e753b13d2d6 | — | |
hash1f378c0efc13669dada1fe340c6837bd | — | |
hash2669731cb5ff664dfb5fbfc37637876d | — | |
hash2ab3df4762fbde5d86e99a1ad147850e | — | |
hash2e76d5316663a3dc472398b1c01cb9a8 | — | |
hash2eb77109cce1e8afca6245c2963e52a6 | — | |
hash302725413076d1aeaee2d7f2b3692646 | — | |
hash30792a0c0dfad55fb2b19d3e30e9a7d4 | — | |
hash37cec428257cd41153cf43d7f1a12652 | — | |
hash3b9d40f3d620ec87960b4350d42ccc03 | — | |
hash3e2110d233d4543830e14c78d53900f4 | — | |
hash422a221851ea6ad15f53cd3aea51c8af | — | |
hash49bdbe7e6cbb88842afcce3a9fe60e9b | — | |
hash4d87fef16790cbe1df72007d99149665 | — | |
hash5577fffb5b5acd3771ef9dc696498f1e | — | |
hash5af95590a33b9bc64d95808f1fc71b78 | — | |
hash5c5672bb14e1d2f07a8318ffec19b213 | — | |
hash6add815cd61d6514f81a23ab8c23405a | — | |
hash73ff669fc282653bd6c42cf87ade9337 | — | |
hash7f12fa589f56f6203c692715b3958d30 | — | |
hash8406075af0a1e9ec09bafdc0de01f138 | — | |
hash8c859a03814443c6f0da341ee594c352 | — | |
hasha1c07ac866fb6b388e38c6bb1d4bbe94 | — | |
hasha343d8bcf02a0554fa271452a512f3ce | — | |
hasha435292106026e257789036a70ee1a14 | — | |
hasha5701848f82c65a55765dc534111899f | — | |
hashaf3fa7f22f6e97901f20326cc12bdb49 | — | |
hashb406ea5b8628cb7801f47c0189b96182 | — | |
hashb50dad56d891ef230656b37ce62cdada | — | |
hashb516ec6c6b37618ad65080a063270ea4 | — | |
hashba0238423b5c29667cd760ccd7b000aa | — | |
hashba8e682a72c6a3e634c070f0fb057bf5 | — | |
hashbbf1b0ab9fc27439de4386ed7b8fc151 | — | |
hashc410055bfa198937825dfd7e41000e7a | — | |
hashc63d021de798034cbf933e1c99bcb83f | — | |
hashc7723bf166ef08ff3112257a1244f584 | — | |
hashca0b57807f79f26e7f59cab2a2542da0 | — | |
hashe0e4aec6d494fe68cdaa52d6878a8366 | — | |
hashe22367800e9d39bc865bd50cddd0537d | — | |
hashead95793528572e7b89679860e2f2116 | — | |
hashed2f8dd9b96d706d833b7aa545b8e621 | — | |
hashf4e7ca8c1de252840c1f0e957cd4b717 | — | |
hashf73e07efb8707e3561e9cbff74557acb | — | |
hash215343916d101c6bbe287871816e063c78103dd1 | — | |
hash263efd45e5cedce553c25cf2c49dbcf28c352cd8 | — | |
hash2b381a3f3e303da8832c8b60120aa6f7486264bf | — | |
hash6bd211981540cd167615e916847e383c5ddb4fbd | — | |
hash7117859ffe0380d6e5e6f9691d6d5f5fc1da20d1 | — | |
hash75ea9f4a55575f39e38c1beb9ec44c0fc7b1c937 | — | |
hash79fcc73e1bcb0b339336c81c8d733bf00bac4001 | — | |
hash984a98b7daeee159ea018a055b86a596c5dccc46 | — | |
hasha1b44d94af77705b075e67b40eb1937cedc55fa8 | — | |
hashb9f25b21eccbcca77adb11a0e613d4eca4e38442 | — | |
hashbeb0ab87b52a417912e0ec84cfa203fd05cae660 | — | |
hashfeaad17999c1a7c768c6d841e790b2f2c006b00f | — | |
hashff6eac85bb9b11d7c1422938235896c8b3a6da3c | — | |
hash018c31af135a0bc5e068df26d866440b28164aa4a659ea7df47bcbaab4a898cd | — | |
hash0432ae814945633b605c77d137bef96c7f84934c682aada69baa326dce781286 | — | |
hash456ed6926b706c203ac65b5174ac2ce78a5dad2ef0f083ae1f0aedd75d811ca2 | — | |
hash4d37b4ccd6e4c0c9de82e66e40dfb6412b92ea33bcf10442a290b0732eeadae0 | — | |
hash5b1f75205cb79a8c8a3d8083f34b552852dfd567dd65763183b7536a29f55f5b | — | |
hasha40a61e54be9cc1671ea6832fef8139ce811a7d759058bb8b4ca86863f4cc1bd | — | |
hashb50422ec3a98d098bb3f7d728012da7e1795221c8b0624562568dff87ab5de2a | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip112.216.9.171 | — | |
ip27.102.137.126 | — | |
ip27.102.138.44 | — | |
ip27.102.137.159 | — |
Threat ID: 6a79f49ebf8831d53900df2e
Added to database: 08/10/2026, 15:56:14 UTC
Last enriched: 08/10/2026, 16:33:14 UTC
Last updated: 08/10/2026, 16:33:14 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.