🧔♂️ A friendly human may check it before it goes live. More news here
North Korean hackers used ChatGPT for phishing attack
A North Korean state-linked hacking group, Kimsuky, used ChatGPT to generate a fake South Korean military ID in a phishing campaign, according to cybersecurity firm Genians.
Researchers said the attackers created a convincing draft of the ID and sent it in emails containing links to data-stealing malware.
Targets included South Korean journalists, researchers, and human rights activists focused on North Korea.
Genians found ChatGPT initially refused to create the ID, but prompt manipulation bypassed the restriction.
The phishing emails came from an address impersonating the South Korean military.
The number of victims was not disclosed.
US officials have accused North Korea of using cyberattacks and IT contractors to collect intelligence and evade sanctions.
🔗 Source: Bloomberg
🧠 Food for thought
Implications, context, and why it matters.
North Korea’s cyber operations have evolved from basic malware to sophisticated AI-assisted attacks
- The Kimsuky group’s use of ChatGPT to create deepfake military IDs represents a significant tactical advancement from North Korea’s earlier cyber campaigns that relied primarily on traditional malware and phishing techniques.
- Previous North Korean cyber operations like the 2017 WannaCry ransomware attack and the 2016 Bangladesh Bank heist used conventional hacking methods, but the new AI-assisted approach shows the regime’s ability to adapt emerging technologies for espionage.
- This evolution mirrors North Korea’s broader cyber strategy, where an estimated 6,000 hackers have conducted increasingly sophisticated operations since 2014, including the Sony Pictures hack.
- The integration of AI tools like ChatGPT into their operations demonstrates how nation-state actors can quickly weaponize commercial AI platforms for intelligence gathering, making their attacks more convincing and harder to detect.
Cyber operations serve as North Korea’s primary sanctions evasion and revenue generation mechanism
- The latest AI-powered attacks continue North Korea’s systematic approach to using cyber capabilities for both intelligence gathering and financial gain, with UN reports showing the regime stole approximately $2 billion through cyberattacks to fund its weapons programs.
- North Korea’s three main cyber groups—Lazarus Group, Bluenoroff, and Andariel—were sanctioned by the US Treasury in 2019 for conducting malicious cyber activities that support the regime’s missile and nuclear programs.
- The Bluenoroff group alone has attempted to steal over $1.1 billion from financial institutions globally, while operations like the Bangladesh Bank heist successfully netted $81 million in 2016.
- These cyber operations allow North Korea to circumvent international sanctions while maintaining plausible deniability, making them a cost-effective alternative to traditional espionage or military actions.
Recent OpenAI developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




