North Korean hackers use AI Tools to forge Military IDs in sophisticated Phishing Attacks

default-cybersecurity-insiders-image

In recent years, we’ve frequently heard about how generative AI tools like ChatGPT—developed by Microsoft and OpenAI—have been misused to craft malware and design convincing phishing emails. However, a new and more sophisticated form of cyberattack has recently come to light.

According to a report from Genians, a cybersecurity firm based in South Korea, a state-sponsored hacking group from North Korea—known as Kimsuky—has begun leveraging artificial intelligence (AI) tools to fabricate fake military identification cards. These forgeries are being used in phishing campaigns to give attackers a sense of credibility and authority, making their requests appear as if they come from legitimate government or military personnel.

How the Attack Works

Security researchers explain that these fake military IDs are used to deceive victims into compliance. For instance, when a hacker initiates a phishing attack, they may present a seemingly authentic military ID to the target. This tactic can lead victims to believe they are interacting with genuine military officials or government employees, making them more likely to share sensitive information or perform requested actions without questioning the source.

The Role of Kimsuky

Kimsuky, active since at least 2020, is a cyber-espionage group believed to be operating under the directive of the North Korean regime. Their main objective is intelligence gathering—particularly information related to foreign governments, defense systems, and international corporations.

One particularly alarming revelation from the Genians report is that Kimsuky operatives have also used Claude, an AI model developed by Anthropic, to pose as Japanese citizens. By doing so, they managed to infiltrate several Fortune 500 companies in the United States, gaining employment under false identities. Once inside these companies, they allegedly collected intelligence on internal operations, projects, and ongoing research and development efforts.

Even more concerning is that these fake employees reportedly used AI tools not only to secure the jobs but also to perform technical tasks, ensuring they could maintain their employment for at least a month without raising suspicion.

Platform Responses and Countermeasures

In response to suspicious activity traced back to accounts connected to North Korean actors, OpenAI took action in February 2025, banning several such accounts. This crackdown has since expanded to include other users from various regions who were found to be exploiting AI technologies for malicious purposes.

Targeting Journalists

Genians’ director, Mun Chong Hyun, also highlighted that forged military IDs were used to intimidate South Korean journalists. These fake credentials served either to dissuade journalists from pursuing sensitive stories or to extract classified information they had gathered, which would normally be reported to the South Korean government.

Who’s Really at Fault?

It’s easy to blame the technology when stories like this come to light. However, it’s important to remember that technology itself is not inherently harmful—it’s a tool. As with any tool, the real threat lies in how it is used and by whom. In this case, it’s the malicious intent behind the misuse of AI that must be identified, isolated, and neutralized—not the technology itself.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display