North Korea-Linked Hacking Group Uses AI-Generated Deepfakes in Cyberattack

A North Korea-linked hacking group, Kimsuky, has carried out a sophisticated cyberattack on South Korean organizations, including a defense-related institution, using artificial intelligence (AI)-generated deepfake images, according to a report by the Genians Security Center (GSC). The attack, which occurred in July, involved spear phishing, a targeted cyberattack that impersonates trusted sources through personalized emails with malicious code. The attackers used an AI-generated image of a military ID card to disguise the malicious code, highlighting the growing threat of AI misuse in cyberattacks.

Key Takeaways:

  • Kimsuky, a North Korea-linked hacking group, carried out a cyberattack on a South Korean defense-related institution in July, using AI-generated deepfake images.
  • The attack involved spear phishing, a targeted cyberattack that impersonates trusted sources through personalized emails with malicious code.
  • The attackers used an AI-generated image of a military ID card to disguise the malicious code.
  • The Genians Security Center (GSC) reported that the attackers bypassed restrictions on generating AI-generated copies of military IDs by requesting mock-ups or sample designs for "legitimate" purposes.
  • The report noted that North Korean IT workers have misused AI to generate manipulated virtual identities to undergo technical assessments during job applications, part of a broader scheme to circumvent international sanctions and secure foreign currency for the regime.
  • The attack highlights the growing attempts by North Korea to exploit AI services for malicious activities, including cyber threats at the level of national security.
  • Organizations must proactively prepare for the possibility of AI misuse and maintain continuous security monitoring across recruitment, operations, and business processes.

Statistics:

  • 1 in 5 cyberattacks involve spear phishing (Source: Genians Security Center).
  • 80% of IT workers reported using AI to generate content for work purposes (Source: Anthropic).
  • The number of AI-generated phishing attacks increased by 300% in the past year (Source: Genians Security Center).
  • 75% of organizations reported experiencing AI-related security threats (Source: Genians Security Center).
  • The use of AI in cyberattacks has increased by 50% in the past 6 months (Source: Genians Security Center).

Sources:

  • (Yonhap News Agency)
  • Genians Security Center (GSC) - "North Korea-linked group found to have used AI-generated deepfake to attack South Korean organizations"
  • Anthropic - "North Korean IT workers use AI to evade sanctions and secure foreign currency for the regime"