North Korean Hackers Turn to AI to Scale Crypto and Financial Attacks
Key Takeaways
- •North Korean-linked hackers are using AI tools such as large language models, coding assistants and document-search systems in cyber operations.
- •Researchers found AI-generated materials designed to look like legitimate financial and cryptocurrency investment documents.
- •Other investigations have linked North Korean operators to AI-created identities and synthetic video setups used to target financial companies.
- •A 2026 financial-sector threat report estimated that North Korea-linked actors stole about $2.02 billion in digital assets in 2025, up 51% from the prior year.
- •Security advisers say crypto and financial firms should strengthen identity checks, train employees and monitor unusual access patterns.

North Korean hackers are increasingly using artificial intelligence to strengthen cyberattacks against cryptocurrency and financial companies, according to new cybersecurity research. The shift signals a broader evolution in how Pyongyang-linked groups combine social engineering, malware and automation to pursue digital assets — a revenue stream that has grown increasingly important for the sanctions-constrained regime.
The activity adds another layer of risk for crypto exchanges, fintech platforms and financial institutions. Security researchers say North Korean operators are no longer treating AI only as a tool for generating convincing phishing messages. Instead, they are integrating AI into multiple stages of their operations. That shift matters because North Korea-linked groups — including those tracked by security firms under names such as Lazarus and APT38 — have already demonstrated an ability to carry out some of the largest cryptocurrency heists on record. Adding AI-driven automation to that foundation could expand the volume and sophistication of campaigns without requiring proportional increases in manpower.
AI Expands the Attack Surface
Recent research found North Korean-linked groups using large language model platforms, AI coding tools and document-search technology during cyber operations. Researchers also identified AI-generated documents designed to resemble legitimate financial and cryptocurrency investment materials.
The technology can help attackers analyze information, create convincing communications and potentially accelerate malware development. Local AI systems can also reduce the need to send sensitive information to external services, making the activity harder to detect — a significant advantage for operators operating under heavy international surveillance and sanctions.
Furthermore, other recent investigations have linked North Korean operators to AI-generated identities and synthetic video environments used to target financial companies. These tactics can make fake recruiters, executives and business contacts appear more credible. The development builds on a well-documented pattern of North Korean operatives posing as legitimate IT workers and recruiters to infiltrate companies, a strategy that Western intelligence agencies have publicly warned about for years.
Crypto Remains a Major Target
The financial incentive remains significant. A major 2026 financial-sector threat report estimated that North Korea-linked actors stole about $2.02 billion in digital assets during 2025. That represented a 51% increase from the previous year. United Nations panels have previously reported that cryptocurrency theft constitutes one of Pyongyang's most important sources of sanctioned revenue, with proceeds linked to weapons programs.
Cryptocurrency companies face particular risks because employees often handle private keys, wallet infrastructure and high-value transactions. Attackers can exploit trusted relationships rather than directly attacking blockchain networks.
The latest developments suggest that AI could make those campaigns faster and more scalable. However, researchers have not established that AI alone is responsible for the attacks or that every reported capability has produced successful theft.
For crypto businesses, the threat reinforces the importance of stronger identity verification, employee security training and monitoring of unusual access. U.S. and allied agencies have issued repeated advisories urging companies to scrutinize remote workers, verify recruiting contacts and harden access controls. As North Korean operators continue adapting their methods, AI is becoming another tool in a long-running campaign focused on espionage and financial gain.