North Korean Hackers Exploit ChatGPT to Create Deepfake Military ID for Phishing Attack

Reviewed byNidhi Govil

9 Sources

Share

A North Korean hacking group, Kimsuky, used OpenAI's ChatGPT to generate a fake South Korean military ID for a sophisticated phishing attack. This incident highlights the growing use of AI tools by state-sponsored hackers for cyber espionage.

North Korean Hackers Leverage ChatGPT for Sophisticated Phishing Attack

In a concerning development at the intersection of artificial intelligence and cybersecurity, a North Korean hacking group known as Kimsuky has been found using OpenAI's ChatGPT to create deepfake military identification cards for a targeted phishing attack against South Korean defense institutions

1

2

3

. This incident, discovered by South Korean cybersecurity firm Genians, highlights the evolving tactics of state-sponsored hackers and the potential misuse of AI technologies in cyber espionage.

The Attack: Methodology and Targets

The phishing campaign, detected in July 2025, involved emails impersonating a South Korean defense-related institution responsible for issuing IDs to military-affiliated officials

1

. The attackers used a domain mimicking an official South Korean military institution and included a malicious .zip file attachment

1

. This file contained a fake government military ID image, which was later found to be generated using OpenAI's GPT-4o model

1

2

.

Source: The Korea Times

Source: The Korea Times

The targets of this sophisticated attack included South Korean journalists, researchers, and human rights activists focused on North Korea

4

. The phishing emails were sent from an address ending in .mil.kr, cleverly impersonating a legitimate South Korean military address

4

5

.

AI-Generated Deepfakes: A New Frontier in Cyber Attacks

The use of ChatGPT to create a convincing deepfake military ID marks a significant escalation in the capabilities of cybercriminals. Genians' analysis revealed that the fake ID image had a 98% probability of being AI-generated

1

. This development is particularly noteworthy because OpenAI has implemented safeguards to prevent the generation of government IDs

1

2

.

However, the Kimsuky group appears to have found a workaround, possibly by framing their requests as creating mock-ups or sample designs for legitimate purposes

1

2

. This technique, known as prompt engineering, allowed the attackers to bypass ChatGPT's built-in restrictions

2

4

.

Broader Implications and Growing Trends

This incident is not isolated but part of a broader trend of North Korean operatives leveraging AI for intelligence gathering and cyber attacks. In August 2025, Anthropic reported that North Korean hackers had used the Claude Code tool to create elaborate fake identities, pass coding assessments, and even secure remote work positions at U.S. Fortune 500 tech companies

3

4

5

.

Source: Economic Times

Source: Economic Times

Security Concerns and Preventive Measures

The successful use of AI in creating convincing fake documents raises significant security concerns. It demonstrates that attackers can leverage emerging AI technologies throughout the hacking process, from attack planning to malware development and social engineering

4

5

.

In response to these threats, AI companies like OpenAI have taken steps to ban suspected North Korean accounts and prevent the misuse of their technologies

3

5

. However, the Kimsuky incident shows that determined attackers can still find ways to exploit these powerful AI tools.

Source: Fortune

Source: Fortune

Conclusion

As AI technologies continue to advance, the cybersecurity landscape faces new challenges. The use of ChatGPT by North Korean hackers to create deepfake military IDs serves as a stark reminder of the need for enhanced security measures and ongoing vigilance in the face of evolving cyber threats. It also underscores the importance of responsible AI development and the need for robust safeguards to prevent the misuse of these powerful tools in cyber warfare and espionage.

Today's Top Stories

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo