North Korean Hackers Stole Money Using AI
Key point
North Korean hackers automated phishing and malware with AI tools, stealing up to $12 million over three months.
Details
Expel revealed that a North Korea-linked group called HexagonalRodent used AI tools such as OpenAI, Cursor, and Anima to automate nearly every stage of intrusion.
The targets were small-scale crypto launches, NFTs, and Web3 developers. Victims were lured in with fake job postings and company websites, then malware was embedded in take-home assignment code to steal credentials, and in some cases, wallet keys as well.
- Infected devices: over 2,000
- Estimated scale: up to $12 million based on total wallet value
- People involved: up to 31
Leaked prompts, English-language comments, and even emojis remained in place, providing strong evidence of AI-generated code. Expel noted that it could not confirm whether some wallets were actually fully emptied.
AI use is also spreading across other North Korean activities. AI is being used for writing resumes, building fake websites, preparing interview answers, researching vulnerabilities, and enhancing malware, and OpenAI and Anthropic have detected related malicious use and blocked accounts. According to the article, OpenAI explained that the core value these tools provide is speed and scale rather than new capabilities.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.