North Korean Hackers Exploit ChatGPT to Launch Deepfake Attack on South Korea

American officials have previously accused North Korea of using cyberattacks, cryptocurrency theft, and recruitment scams to gather intelligence and finance its nuclear weapons development program

1 min read
North Korean leader Kim Jong Un visits one of his country's nuclear material production facilities at an undisclosed location. [Photo: KCNA]

A suspected North Korean state-sponsored hacking group reportedly used artificial intelligence tools, including ChatGPT, to create a deepfake military ID document in a phishing attack targeting South Korean citizens, according to cybersecurity researchers.

The hacking group, known as Kimsuky, is believed to be operating under orders from the North Korean regime to conduct global intelligence-gathering operations. Kimsuky has previously been linked to espionage efforts aimed at South Korean targets, and is described by the U.S. Department of Homeland Security as “most likely tasked by the North Korean regime with a global intelligence-gathering mission.”

In the latest attack, the hackers crafted a fake draft of a South Korean military ID using ChatGPT to generate a highly realistic-looking image. The forged document was used to bolster a phishing email’s credibility, with the aim of tricking recipients into downloading malware. Rather than embedding an actual image, the email contained a malicious link capable of extracting sensitive data from the victim’s devices.

The phishing emails were sent to journalists, researchers, and human rights activists focused on North Korea. The messages were dispatched from an email address mimicking a legitimate military domain (.mil.kr), further adding to the deception. While the total number of victims affected by the attack remains unknown, researchers warn that the campaign represents a significant escalation in the use of AI tools for cyber-espionage.

AI Tools in Cyber Warfare

This is not the first instance of North Korean actors leveraging artificial intelligence in their operations. In August, cybersecurity firm Anthropic revealed that hackers linked to North Korea used the AI tool Claude Code to create elaborate fake identities, pass technical interviews, and secure employment at U.S. Fortune 500 tech firms. Similarly, OpenAI confirmed earlier this year that it had banned accounts connected to North Korean actors attempting to create fraudulent résumés and recruitment profiles to expand their network.

“Attackers are increasingly using emerging AI technology not just to craft attack scenarios, but also to develop malware, build tools, and impersonate job recruiters,” said Mun Chong-hyun, director at Genians, the South Korean cybersecurity firm that uncovered the latest incident.

Bypassing Safeguards

During their investigation, Genians researchers tested ChatGPT’s safeguards. When initially asked to generate a military ID, ChatGPT refused, citing legal restrictions in South Korea. However, the researchers found that by altering the prompt, they could bypass these restrictions—a concerning loophole that attackers exploited.

Wider Implications

American officials have previously accused North Korea of using cyberattacks, cryptocurrency theft, and recruitment scams to gather intelligence and finance its nuclear weapons development program, while circumventing international sanctions. The latest campaign underscores how AI tools are becoming a force multiplier for state-backed cyber operations.

As AI continues to evolve, experts warn that attackers will further refine their methods, blending machine learning capabilities with traditional espionage tactics to craft increasingly sophisticated campaigns.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog