North Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling that could accelerate analysis of stolen calls, meetings, and documents. The operation retains Kimsuky’s established use of spear-phishing lures, malicious Windows shortcut files, PowerShell loaders, and Git-based […]
Read the original article: