A suspected North Korean state-sponsored hacking group used ChatGPT to create a deepfake of a military ID document to attack a target in South Korea, according to cybersecurity researchers.
Attackers used the artificial intelligence tool to make a fake draft of a South Korean military identification card to create a realistic-looking image meant to make a phishing attempt seem more credible, said the research published on Sunday by Genians, a South Korean cybersecurity firm. Instead of including a real image, the email linked to malware capable of extracting data from recipients’ devices, according to Genians.
The group responsible for the attack, which researchers have dubbed Kimsuky, is a suspected North Korea-sponsored cyberespionage unit previously linked to other spying efforts against South Korean targets. The US Department of Homeland Security said Kimsuky “is most likely tasked by the North Korean regime with a global intelligence-gathering mission”, according to a 2020 advisory.
ChatGPT initially refused to create the IDs, but altering the prompt allowed hackers to bypass this restriction. Photo: AFP
The findings by Genians in July are the latest example of suspected North Korean operatives deploying AI as part of their intelligence-gathering work. Anthropic said in August it discovered North Korean hackers used the Claude Code tool to get hired and work remotely for US Fortune 500 tech companies. In that case, Claude helped them build up elaborate fake identities, pass coding assessments and deliver actual technical work once hired.
OpenAI representatives did not immediately respond to a request for comment outside normal working hours. The company said in February it had banned suspected North Korean accounts that had used the service to create fraudulent résumés, cover letters and social media posts to try recruiting people to aid their schemes.
The trend shows that attackers can leverage emerging AI during the hacking process, including attack scenario planning, malware development, building their tools and impersonating job recruiters, said Mun Chong-hyun, director at Genians.
Phishing targets in this latest cybercrime spree included South Korean journalists and researchers and human rights activists focused on North Korea. It was also sent from an email address ending in .mil.kr, an impersonation of a South Korean military address.
The Philippines is targeting to recruit more coders, engineers and cybersecurity specialists into the military, as Manila confronts a battlefield increasingly shaped by software, networks…
The United States has imposed sanctions on two companies and six individuals for their roles in operations that used information technology workers in foreign countries…
Foreign spies in China have disguised themselves as wedding photographers near naval ports, or have collected mapping data using advanced radar and GPS optical lenses…
Jiang Xiaojuan, former deputy secretary general of the State Council, said at the Boao Forum for Asia annual conference in Hainan province that precaution was…
A Philippine tech company has been sanctioned by the United States for allegedly enabling online romance scams known as “pig butchering”, which US authorities say…
Hong Kong police have arrested 118 people in a citywide crackdown on online shopping scams involving losses of more than HK$5 million (US$636,940), largely linked…