logo

AI Tools Are Helping Mediocre North Korean Hackers Steal Millions

ID: 32ec4e98-17c0-5b9d-a495-a571abdb01bb

STIX ID: report--32ec4e98-17c0-5b9d-a495-a571abdb01bb

Feed Name: WIRED Security

Threat Score
86/100

Date Published: 2026-04-22

Date Updated: 2026-04-26

Author: Andy Greenberg, Matt Burgess

...
...

Expel disclosed a North Korean state-sponsored operation, HexagonalRodent, that leveraged AI tools (including OpenAI, Cursor, and Anima) to generate phishing sites, malware-laced coding tests, and other infrastructure targeting crypto/NFT/Web3 developers; the campaign infected more than 2,000 machines and may have facilitated up to $12 million in stolen cryptocurrency while also leaving parts of its infrastructure exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.