AI Tools Are Helping Mediocre North Korean Hackers Steal Millions
Recent investigations reveal that North Korean cybercriminals are using AI technologies to enhance their hacking capabilities. Even groups with limited technical expertise are now able to deploy effective malware campaigns and steal significant assets, particularly within the cryptocurrency sector.
AI Empowers Inexperienced Hackers
A North Korean group, referred to as HexagonalRodent by cybersecurity firm Expel, orchestrated attacks that targeted thousands of cryptocurrency developers and startups. Utilizing AI services from companies like OpenAI, Cursor, and Anima, these hackers automated every step of their operations—from coding malware and building fake company websites to managing phishing campaigns. These coordinated campaigns reportedly netted them up to $12 million in just a few months.
How the Attacks Work
The hackers mainly targeted developers in crypto and Web3 projects, tricking them with fake job offers and coding assignments. Once victims downloaded what they believed was a test, their systems were infected with credential-stealing malware, often written and commented in English, and sometimes marked with emojis—signs that generative AI was used for development.
Ironically, the hackers were careless enough to leave their infrastructure exposed, which allowed researchers to trace the operations and estimate the extent of the losses. While their malware was not sophisticated enough to bypass standard enterprise security tools, their focus on individual victims increased success against less-protected targets.
AI as a Force Multiplier
Experts highlight that AI has become an essential tool for North Korea's cyber units, many of whom lack advanced computer training but can use generative AI to operate as skilled hackers. AI's speed, scalability, and usability lower the barrier for running complex cyberattacks, making it easier for such groups to recruit and train new members rapidly.
Broader Implications
North Korea continues to invest in AI for cyber operations, reportedly developing new in-house capabilities while also exploiting commercial AI services for malicious purposes. Tech firms like OpenAI, Anthropic, Cursor, and Anima are actively working to identify and block North Korean abuse of their platforms, but the problem persists.
A Changing Cybersecurity Landscape
Rather than enabling highly sophisticated attacks, AI is empowering more individuals to participate in cybercrime by automating tasks, creating phishing infrastructure, and fabricating identification tools. The focus for cybersecurity professionals should be on countering these real-world threats emerging from AI-enabled hacking, rather than only preparing for hypothetical, advanced AI assaults.
For more details and the original investigative reporting, visit the full article on WIRED.