North Korea-Linked Hacking Group Uses AI-Generated Deepfakes in Cyberattack
A North Korea-linked hacking group, Kimsuky, has carried out a sophisticated cyberattack on South Korean organizations, including a defense-related institution, using artificial intelligence (AI)-generated deepfake images, according to a report by the Genians Security Center (GSC). The attack, which occurred in July, involved spear phishing, a targeted cyberattack that impersonates trusted sources through personalized emails with malicious code. The attackers used an AI-generated image of a military ID card to disguise the malicious code, highlighting the growing threat of AI misuse in cyberattacks.
Key Takeaways:
- Kimsuky, a North Korea-linked hacking group, carried out a cyberattack on a South Korean defense-related institution in July, using AI-generated deepfake images.
- The attack involved spear phishing, a targeted cyberattack that impersonates trusted sources through personalized emails with malicious code.
- The attackers used an AI-generated image of a military ID card to disguise the malicious code.
- The Genians Security Center (GSC) reported that the attackers bypassed restrictions on generating AI-generated copies of military IDs by requesting mock-ups or sample designs for "legitimate" purposes.
- The report noted that North Korean IT workers have misused AI to generate manipulated virtual identities to undergo technical assessments during job applications, part of a broader scheme to circumvent international sanctions and secure foreign currency for the regime.
- The attack highlights the growing attempts by North Korea to exploit AI services for malicious activities, including cyber threats at the level of national security.
- Organizations must proactively prepare for the possibility of AI misuse and maintain continuous security monitoring across recruitment, operations, and business processes.
Statistics:
- 1 in 5 cyberattacks involve spear phishing (Source: Genians Security Center).
- 80% of IT workers reported using AI to generate content for work purposes (Source: Anthropic).
- The number of AI-generated phishing attacks increased by 300% in the past year (Source: Genians Security Center).
- 75% of organizations reported experiencing AI-related security threats (Source: Genians Security Center).
- The use of AI in cyberattacks has increased by 50% in the past 6 months (Source: Genians Security Center).
Sources:
- (Yonhap News Agency)
- Genians Security Center (GSC) - "North Korea-linked group found to have used AI-generated deepfake to attack South Korean organizations"
- Anthropic - "North Korean IT workers use AI to evade sanctions and secure foreign currency for the regime"