Lead
State-sponsored hackers from North Korea and China have demonstrated "significant interest" in leveraging artificial intelligence to detect previously unknown cybersecurity vulnerabilities, Alphabet's Google said in a report released Tuesday. The report, from Google's threat intelligence group, highlighted a growing trend among these state-linked actors to use AI in their cyber operations, marking a shift in how such attacks may be planned and executed.
Coverage Comparison
Two separate reports, both carried by Yonhap News, shed light on the increasing role of AI in cyber threats originating from the Korean Peninsula. The first, based on Google's findings, focuses on the use of AI to identify and exploit vulnerabilities. The second, drawing on research from Russian cybersecurity firm Kaspersky, details how a specific North Korean hacking group, Kimsuky, has adopted AI to develop malicious software targeting South Korean government systems.
While both reports emphasize the growing sophistication of North Korean cyber capabilities, they approach the topic from different angles. The Google report, as summarized by Yonhap, centers on the broader trend of AI-assisted vulnerability research, noting that clusters of threat activity associated with both the People's Republic of China (PRC) and the Democratic People's Republic of Korea (DPRK) have shown particular interest. In contrast, the Kaspersky report provides a detailed case study of one group's tactics, linking AI to specific malware development.
Key Claims
Google's threat intelligence group reported that it observed a particular interest in AI from several clusters of threat activity associated with the PRC and DPRK. The report specifically mentioned a recent attempt by North Korea's hacking group APT45, which leveraged AI to send thousands of repetitive prompts that recursively analyzed different cybersecurity blind spots for possible exploitation.
The same report noted that Google used its own AI tools to detect hackers from a criminal group planning to use a "zero-day exploit" in a "mass exploitation." The incident marked the first time Google identified attackers using AI to find new vulnerabilities and exploit them on a mass scale, according to Yonhap's coverage of the report. Zero-day exploits refer to vulnerabilities that organizations and developers are unaware of before an attack occurs, leaving no time to respond.
The Google report arrives amid renewed global concerns over cybersecurity, following the introduction of Claude Mythos, an AI model from U.S. startup Anthropic that specializes in detecting software security vulnerabilities. Anthropic has decided not to release the model publicly, limiting its access to a select number of companies and institutions for defense security testing.
Separately, Kaspersky reported that its researchers discovered a backdoor malware program called "HelloDoor," first identified last August, was linked to the North Korean hacking group Kimsuky. The report said that comments in the code "appear to have been generated by a large language model (LLM) service rather than a human developer," based on traces including emojis used for logging debugging messages.
The Kaspersky report also highlighted new cyberattack tactics employed by Kimsuky. Since last year, the group has been using a feature called "Visual Studio Code Remote Tunneling" to establish covert remote access to victims' devices, rather than deploying malware directly.
Kaspersky noted that these advancements pose greater threats, particularly to South Korean government institutions, which have been the primary targets of the hacking group. Specifically, Kimsuky's "AppleSeed" malware is mainly used to extract key data from the South Korean government's authentication system used on government servers. The report warned that if authentication data is compromised, hackers could gain unauthorized access to internal government systems through hijacked accounts, posing a broader security threat to the nation's infrastructure.