By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Online Tech Guru
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Reading: AI Tools Are Helping Mediocre North Korean Hackers Steal Millions
Best Deal
Font ResizerAa
Online Tech GuruOnline Tech Guru
  • News
  • Mobile
  • PC/Windows
  • Gaming
  • Apps
  • Gadgets
  • Accessories
Search
  • News
  • PC/Windows
  • Mobile
  • Apps
  • Gadgets
  • More
    • Gaming
    • Accessories
    • Editor’s Choice
    • Press Release
Action-Focused Roguelite Dragon Quest Smash/Grow Launches on iOS and Android

Action-Focused Roguelite Dragon Quest Smash/Grow Launches on iOS and Android

News Room News Room 22 April 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow
  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Online Tech Guru > News > AI Tools Are Helping Mediocre North Korean Hackers Steal Millions
News

AI Tools Are Helping Mediocre North Korean Hackers Steal Millions

News Room
Last updated: 22 April 2026 18:35
By News Room 5 Min Read
Share
AI Tools Are Helping Mediocre North Korean Hackers Steal Millions
SHARE

The advent of AI hacking tools has raised fears of a near future in which anyone can use automated tools to dig up exploitable vulnerabilities in any piece of software, like a kind of digital intrusion superpower. Here in the present, however, AI seems to be playing a more mundane, if still concerning, role in hackers’ toolkit: It’s helping mediocre hackers level up and carry out broad, effective malware campaigns. That includes one group of relatively unskilled North Korean cybercriminals who’ve been discovered using AI to carry out virtually every part of an operation that hacked thousands of victims to steal their cryptocurrency.

On Wednesday, cybersecurity firm Expel revealed what it describes as a North Korean state-sponsored cybercrime operation that installed credential-stealing malware on more than 2,000 computers, specifically targeting the machines of developers working on small cryptocurrency launches, NFT creation, and Web3 projects. By using the AI tools of US-based companies, including those of OpenAI, Cursor, and Anima, the hacker group—which Expel calls HexagonalRodent—“vibe coded” almost every part of its intrusion campaign, from writing their malware to building the fake websites of companies used in its phishing schemes. That AI-enabled hacking allowed the group to steal as much as $12 million in cryptocurrency from victims in three months.

What’s most striking about the HexagonalRodent hacking campaign isn’t its sophistication, says Marcus Hutchins, the security researcher who discovered the group, but rather how AI tools allowed an apparently unsophisticated group to carry out a profitable theft spree in the service of the North Korean state.

“These operators don’t have the skills to write code. They don’t have the skills to set up infrastructure. AI is actually enabling them to do things that they otherwise just would not be able to do,” says Hutchins, who became well-known in the cybersecurity community after disabling the WannaCry ransomware worm created by North Korean hackers.

Emoji-Littered, AI-Written Code

HexagonalRodent’s hacking operation focused on tricking crypto developers with fraudulent job offers at tech firms, going so far as to create full websites for the fake companies recruiting the victims, often created with AI web design tools. Eventually, the victim was told they’d have to download and complete a coding assignment as a test—which the hackers had infected with malware that infiltrated their machine and stole credentials, including those that in some cases could grant access to the keys that controlled their crypto wallets.

Those parts of the hacking operation appear to have been well-honed and effective, but the hackers were also clumsy enough to leave parts of their own infrastructure unsecured, leaking the prompts they used to write their malware with tools that included OpenAI’s ChatGPT and Cursor. They also exposed a database where they tracked victim wallets, which allowed Expel to estimate the total amount of cryptocurrency the hackers may have stolen. (While those wallets added up to $12 million in total contents, Hutchins says the company couldn’t confirm for each target whether the entire sum had already been drained from the wallets or if the hackers still needed to obtain keys to the victim wallets in some cases, given some may have been protected with hardware security tokens.)

Hutchins also analyzed samples of the hackers’ malware and found other clues that it was largely—perhaps entirely—created with AI. It was thoroughly annotated with comments throughout—in English—hardly the typical coding habits of North Koreans, despite the fact that some command-and-control servers for the malware tied them to known North Korean hacking operations. The malware’s code was also littered with emojis, which Hutchins points out can, in some cases, serve as a clue that software was written by a large language model, given that programmers writing on a PC keyboard rather than a phone rarely take the time to insert emojis. “It’s a pretty well-documented sign of AI-written code,” Hutchins says.

Share This Article
Facebook Twitter Copy Link
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Ember’s self-heating smart mug is more than  off ahead of Mother’s Day

Ember’s self-heating smart mug is more than $50 off ahead of Mother’s Day

News Room News Room 22 April 2026
FacebookLike
InstagramFollow
YoutubeSubscribe
TiktokFollow

Trending

Anthropic’s Mythos rollout has missed America’s cybersecurity agency

Several US federal agencies are taking up Anthropic’s new cybersecurity model to find vulnerabilities, but…

22 April 2026

US hardware sales rose 69% in March 2026 following strong Switch 2 performance | US Monthly Charts

Total US consumer spending on video games jumped 12% to $5.3 billion in March 2026,…

22 April 2026

New York Bans Government Employees from Insider Trading on Prediction Markets

New York has banned state employees from using insider information to trade on prediction markets.…

22 April 2026
News

5 AI Models Tried to Scam Me. Some of Them Were Scary Good

5 AI Models Tried to Scam Me. Some of Them Were Scary Good

I recently witnessed how scary-good artificial intelligence is getting at the human side of computer hacking, when the following message popped up on my laptop screen:Hi Will,I’ve been following your…

News Room 22 April 2026

Your may also like!

Microsoft says the ‘idea’ of an Xbox mobile store ‘is not dead’
News

Microsoft says the ‘idea’ of an Xbox mobile store ‘is not dead’

News Room 22 April 2026
New Lara Croft Voice Alix Wilton Regan on Sophie Turner Casting
Gaming

New Lara Croft Voice Alix Wilton Regan on Sophie Turner Casting

News Room 22 April 2026
USAID Whistleblower Says It Was Even Worse Than People Knew
News

USAID Whistleblower Says It Was Even Worse Than People Knew

News Room 22 April 2026
I bought Alienware’s 0 OLED monitor and I can’t believe how good it is
News

I bought Alienware’s $350 OLED monitor and I can’t believe how good it is

News Room 22 April 2026

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site.

Read our privacy policy for more information.

Quick Links

  • Subscribe
  • Privacy Policy
  • Contact
  • Terms of Use
Advertise with us

Socials

Follow US
Welcome Back!

Sign in to your account

Lost your password?