AI Tools

AI Tools Enable North Korean Hackers to Steal $12 Million

A group of North Korean hackers, dubbed HexagonalRodent by cybersecurity firm Expel, used AI tools from OpenAI, Cursor, and Anima to conduct a cybercrime operation. They targeted crypto developers with fake job offers and malware, stealing up to $12 million in cryptocurrency over three months. Security researcher Marcus Hutchins notes that AI allowed unskilled operators to execute the campaign effectively.

Neura News

Neura News

Neura Market Editorial

April 22, 20265 min read

Originally reported by wired.com

AI Tools Enable North Korean Hackers to Steal $12 Million

AI Tools Enable North Korean Hackers to Steal $12 Million

A team of North Korean cybercriminals has relied on AI tools to handle nearly every aspect of a hacking effort that targeted thousands of victims and took up to $12 million in cryptocurrency during three months. Cybersecurity company Expel detailed the operation on Wednesday. The group, which Expel named HexagonalRodent, focused on developers involved in small cryptocurrency projects, NFT development, and Web3 work. The hackers installed credential-stealing malware on over 2,000 computers.

The attackers drew on AI services from American firms such as OpenAI, Cursor, and Anima. They used these tools to produce their malware code and to construct phony company websites for phishing attacks. This approach let a seemingly low-skill group achieve significant financial gains, likely in support of North Korean state interests.

HexagonalRodent's Tactics and Discoveries

Security researcher Marcus Hutchins, who identified the group, emphasized that the operation's success came not from advanced techniques but from AI assistance. Hutchins gained fame in cybersecurity circles for stopping the WannaCry ransomware, a program linked to North Korean hackers. "These operators don't have the skills to write code. They don't have the skills to set up infrastructure. AI is actually enabling them to do things that they otherwise just would not be able to do," Hutchins stated.

The hackers posed fake job offers from tech companies to lure crypto developers. They built complete websites for these nonexistent firms, often with AI-powered web design tools. Victims received instructions to download a coding test, which carried malware. This software stole login details and, in some instances, access to cryptocurrency wallet keys.

Traces of the hackers' work exposed their methods. They left prompts visible from tools like OpenAI's ChatGPT and Cursor. A leaked database showed victim wallets totaling $12 million, though Expel could not verify if all funds had been fully extracted. Some wallets might have required additional steps due to hardware security tokens.

Clues in the AI-Generated Malware

Analysis of the malware samples revealed heavy AI involvement. The code featured English comments throughout, unusual for North Korean coders. Emojis appeared frequently in the code, a sign often linked to large language models, as typical programmers on computers rarely add them. "It's a pretty well-documented sign of AI-written code," Hutchins noted. Command-and-control servers connected the malware to established North Korean hacking groups.

Standard endpoint detection tools should have caught the malware, which followed common patterns. However, many individual targets lacked such protections. "They found a niche where you actually can get away with completely AI-generated malware," Hutchins said.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

North Korea maintains a large pool of IT workers sent abroad or posing as foreigners in tech firms, but few possess real hacking expertise due to limited domestic access to computers and the internet. "They have hundreds of people being sent over the border to work in IT operations, and only a few of them really know what they're doing," Hutchins explained. AI helps these workers conduct successful attacks. Expel counted up to 31 individuals in the HexagonalRodent effort, showing operations expanding with AI support rather than shrinking.

North Korea's Growing Reliance on AI

This campaign represents a fraction of North Korea's extensive cyber efforts, which include massive cryptocurrency heists, ransomware, spying, fraud, and IT worker infiltration schemes. Experts describe these as a state-sanctioned crime network funding nuclear programs, infrastructure, and sanctions evasion.

North Korean groups increasingly integrate generative AI into their activities. The country established Research Center 227 under the military's Reconnaissance General Bureau to develop AI-based hacking tools. Operators frequently use commercial AI products.

"North Korea is using AI as a force multiplier, and it is helping with every aspect, building resumes, building websites, building exploits, testing vulnerabilities, and they're doing it at speed and scale," said Michael "Barni" Barnhart, a DTEX researcher tracking North Korean hacks for years. Barnhart noted experiments with AI over multiple years to speed up exploit creation.

IT workers have employed AI for interview prep, deepfakes, and more. Microsoft researchers found North Korean actors using AI for fake IDs, tool research, English improvement, social engineering, and vulnerability scouting. They also scaled web setups to evade detection.

OpenAI and Anthropic detected and banned North Korean users in the past 12 months. OpenAI blocked accounts in IT fraud schemes, including interview responses and code writing. Anthropic's August report highlighted IT workers needing AI for basic tasks and hackers trying to improve malware like Expel's finds or create infected tests. Both firms acted swiftly.

OpenAI stated its tools offered no new abilities to the hackers but aided in speed and scale. Cursor confirmed blocking HexagonalRodent and coordinating with others. Anima's CEO Avishay Cohen said they addressed the misuse with Expel.

Hutchins urged focus on current AI misuse over future threats. "We're thinking we need to build defenses for the hypothetical Skynet that's going to blast through all of our networks," he said. "Meanwhile, you have a nation-state threat who is able to spin up their operations using AI without doing anything novel. There is real threat activity happening as a result of AI. But it's not the stuff that people are wasting their breath on."

Related on Neura Market

More from Neura News

AI Models

Google Unveils Gemini 3.6 Flash, 3.5 Flash-Lite, and Cyber Model

Google has released three new Gemini models: 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber. The 3.6 Flash model offers improved coding and knowledge work with 17% fewer output tokens and lower costs. The 3.5 Flash-Lite is the fastest in the series at 350 tokens per second, designed for high-throughput agentic tasks. The 3.5 Flash Cyber model, available only to governments and trusted partners via CodeMender, focuses on finding and fixing cybersecurity vulnerabilities. Google also noted that Gemini 3.5 Pro is being tested with partners and that pre-training for Gemini 4 has begun.

Jul 21·5 min read
AI Models

Alibaba Qwen-Image-3.0 renders infographics and tiny text in one pass

Alibaba's Qwen team released Qwen-Image-3.0, an image generator designed for practical applications like newspaper layouts and complex infographics. The model processes prompts of up to 4,500 tokens and can render legible text as small as ten pixels, mathematical formulas, and twelve languages in a single pass. It is currently available through invite-only API access, with plans to integrate it into first-party apps like Qwen Chat soon.

Jul 21·4 min read
AI Models

Google Unveils Gemini 3.6 Flash, 3.5 Flash-Lite, and Cyber Model

Google DeepMind has introduced three new Gemini models: 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber. The 3.6 Flash model offers improved coding and multimodal performance with 17% fewer output tokens and lower cost. The 3.5 Flash-Lite is the fastest in its series at 350 output tokens per second, designed for high-throughput agentic tasks. The 3.5 Flash Cyber, fine-tuned for cybersecurity, will be available exclusively to governments and trusted partners via the CodeMender agent.

Jul 21·6 min read