The North Korean hacking group Kimsuky is reportedly leveraging AI coding agents to automate the creation of phishing lures. Researchers at Genians observed the group using an AI agent, identified as OpenCode, to generate a high volume of convincing financial and corporate-themed decoy documents. These lures are then packaged within malicious Windows shortcut files, which, when opened, initiate a chain of commands to download further payloads and establish persistence on the victim's system. AI
IMPACT This development highlights the increasing use of AI tools by malicious actors to scale cyberattacks, potentially increasing the sophistication and volume of phishing campaigns.
RANK_REASON The item describes the use of an AI tool by a threat actor for malicious purposes, rather than a new AI model release or core AI research.
Read on Mastodon — fosstodon.org →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →