North Korea-linked Kimsuky hacking group used AI coding agents to create malicious decoys, South Korean firm reports
Quick Look
South Korean security firm Genians Inc. reported that North Korea-linked hacking group Kimsuky used the open-source AI coding agent opencode to create decoy documents for malware distribution, based on analysis of 13 malicious files collected last month.
AI-generated summary
Why It Matters
Genians Inc. previously detected Kimsuky using large language models to create decoys and plan malicious attacks. This latest finding shows the group's evolution in using AI coding agents for malware distribution.
SEOUL, Sept. 7 (Yonhap) -- North Korea-linked hacking group Kimsuky was found to have leveraged artificial intelligence (AI) coding agents to create decoys for malicious codes, a local security firm said Monday.
Such findings were detected after an analysis of 13 malicious files collected last month, Genians Inc. said in its latest cybersecurity threat intelligence report.
According to the report, researchers found that the hacking group distributed emails attached with compressed files holding documents with titles such as "insurance bills," or "policy fund notice". They activated malware when users click them, the report said.
The files contained traces of being created by an open-sourced AI coding agent called opencode.
"In some of the PDF documents, both the 'creator' and 'producer' fields in the metadata were listed as 'opencode,'" the report said.
"These are not values typically generated with standard document creation software, strongly suggesting the documents were generated by an AI agent, through programming, rather than created manually."
Genians said it marks the first time that the company has detected signs of Kimsuky utilizing AI coding agents in its malicious attacks.
Earlier, the company said it detected signs of the hacking group using large language models (LLM) to create decoys and plan malicious attacks.
What to Watch
AI outlook โ possibilities, not facts
Kimsuky will continue to integrate AI tools into its cyberattack methodologies
Likely ยท Within months
Open Questions
- What specific types of malware were distributed via the AI-generated decoys?
- Which countries or organizations were targeted in this campaign?
- How effective were the AI-generated decoys in evading detection?







