LIVE FEED
Kimsuky Runs Offline LLMs to Sharpen Phishing, Build Malware

Kimsuky Runs Offline LLMs to Sharpen Phishing, Build Malware

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 8.5 The Hacker News

North Korean APT group Kimsuky has assembled a private, offline AI stack — including Ollama, GPT4All, and RAG tooling — to enhance spear-phishing lure quality and automate malware development in C#/.NET. South Korean firm Genians found configured instances of these tools on Kimsuky-linked infrastructure, alongside developer libraries such as LLaMaSharp and Microsoft Semantic Kernel, indicating deliberate integration of AI into the group's attack pipeline. The shift erodes traditional phishing detection signals like poor grammar and formatting, forcing defenders to pivot toward behavioural indicators on the endpoint.

GreyVibe Deploys ChatGPT and Gemini in LLM Attack Chain

GreyVibe Deploys ChatGPT and Gemini in LLM Attack Chain

ATLAS OWASP HIGH Significant risk · Prioritise patching ▲ 7.5 SecurityWeek

WithSecure has documented GreyVibe, a Russia-nexus threat actor systematically deploying ChatGPT, Google Gemini, and Ideogram AI across every phase of its attack chain — from phishing lure creation to custom malware development — against Ukrainian targets since August 2025. The group's LLM-assisted malware, LegionRelay, contained design flaws introduced during AI-generated development, which paradoxically allowed researchers to track the group over an extended period. The case illustrates both the operational leverage AI provides to moderately skilled threat actors and the novel forensic signatures that AI-assisted development can inadvertently introduce.

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.