North Korean Hackers Exploit ChatGPT to Create Deepfake Military ID for Cyber Espionage

Reviewed byNidhi Govil

2 Sources

Share

A suspected North Korean hacking group used ChatGPT to forge a fake South Korean military ID for a phishing attack. This incident highlights the growing use of AI tools by state-sponsored hackers for cyber espionage.

News article

North Korean Hackers Leverage AI for Sophisticated Phishing Attack

A suspected North Korean state-sponsored hacking group, known as Kimsuky, has taken cyber espionage to new heights by utilizing ChatGPT to create a deepfake South Korean military identification card. This sophisticated phishing attempt targeted South Korean journalists, researchers, and human rights activists focused on North Korea, according to research published by Genians, a South Korean cybersecurity firm

1

.

The Anatomy of the Attack

The attackers employed ChatGPT to craft a realistic-looking fake draft of a South Korean military ID. Instead of including a real image, the phishing email linked to malware capable of extracting data from recipients' devices

1

. To add credibility to their scheme, the hackers sent the phishing emails from an address ending in .mil.kr, impersonating a South Korean military address

2

.

Kimsuky: A Known Threat Actor

Kimsuky is a suspected North Korea-sponsored cyber-espionage unit previously linked to other spying efforts against South Korean targets. The US Department of Homeland Security has stated that Kimsuky "is most likely tasked by the North Korean regime with a global intelligence-gathering mission," according to a 2020 advisory .

AI: A Double-Edged Sword in Cybersecurity

This incident is not an isolated case of North Korean operatives deploying AI for intelligence gathering. In August, Anthropic discovered that North Korean hackers used the Claude Code tool to get hired and work remotely for US Fortune 500 tech companies, building elaborate fake identities and passing coding assessments .

Implications and Countermeasures

The trend demonstrates that attackers can leverage emerging AI technologies throughout the hacking process, including attack scenario planning, malware development, tool building, and impersonation of job recruiters. Mun Chong-hyun, director at Genians, emphasized the versatility of AI in cybercrime .

OpenAI has taken steps to combat such misuse, banning suspected North Korean accounts that had used their service to create fraudulent rΓ©sumΓ©s, cover letters, and social media posts for recruitment schemes .

The Broader Context of North Korean Cyber Activities

American officials allege that North Korea is engaged in a long-running effort to use cyberattacks, cryptocurrency theft, and IT contractors to gather information and generate funds for the regime in Pyongyang. These tactics are reportedly aimed at subverting international sanctions and supporting North Korea's nuclear weapons programs .

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

Β© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo