The Takeaway
North Korea is using artificial intelligence (AI) to automate its analysis of stolen information, generate more persuasive phishing materials, accelerate malware development, and disguise the identities of its legion of cybercriminals. These tactics, and the technology behind them, increase the threat to Canada and other vulnerable Indo-Pacific states.
North Korea’s AI-automated cyberattacks are largely financially motivated and increasingly focused on cryptocurrency. As Pyongyang becomes more adept at exploiting generative AI to target highly connected financial, technology, research, and critical-infrastructure sectors, Canada will need to strengthen its international collaboration, including with Japan, South Korea, and the U.S., which are also frequent targets of North Korea-backed cybercrime.
In Brief
- On August 10, 2026, South Korean cybersecurity firm Genians reported that Kimsuky, a North Korean hacking group, is building and using locally run AI systems to analyze stolen data and create more sophisticated phishing campaigns. This suggests a shift from simply using generative AI for deceptive content toward integrating AI more deeply into broader cyber operations, including malware development and automated cyberattacks.
- North Korea pursues cryptocurrency theft as it directly generates hard currency for the heavily sanctioned regime. In 2025, North Korean actors stole an estimated US$2.02 billion in cryptocurrency, and in the first half of 2026, just two attacks, also attributed to North Korea, accounted for over US$500 million in losses. As Pyongyang continues to face economic sanctions, the benefits of cybercrime far outweigh the costs — these stolen assets reportedly contribute anywhere from one-third to one-half of the country’s annual budget. This fast-rising state-sponsored cybercrime ecosystem generates illicit revenue for the regime to support its strategic and military objectives, which are at odds with Canadian interests.
- AI makes these cybercrimes harder to detect. North Korea uses stolen identities to create credible digital personas and secure remote jobs at foreign companies, generating illicit revenue and potentially gaining insider access to corporate systems. AI tools such as generative AI for résumés, AI-image editing and face-swapping, and voice-changing software make these encounters more convincing. Not only does AI help North Korean IT workers create more realistic professional materials, but these crimes are increasingly intertwined with legitimate technology ecosystems, making detection more difficult.
- On July 31, for the first time, Canada joined 10 like-minded partners — Australia, France, Germany, Italy, Japan, the Netherlands, New Zealand, South Korea, the U.K., and the U.S. — in a joint statement, warning that North Korean IT workers are using false identities, third-country proxies, and even “laptop farms” to obtain overseas employment to funnel income to North Korea’s illicit weapons programs. The July joint statement, coming on the heels of an FBI disclosure of an ongoing investigation into North Korean IT workers, is likely an effort by Canada to match an August 2025 statement by the U.S., Japan, and South Korea, and reflects Canada’s burgeoning cybersecurity co-operation with Japan and South Korea.
Implications
For Canada, the targets of North Korea’s AI-powered cybercrime will shift from government organizations to industry and business actors with high-value digital assets. Canadian firms can be targeted indirectly through their contractors, employees, cloud services, software dependencies, or third-party technology providers.
The recent use of fake employment and interview schemes is particularly relevant to Canada's growing advanced technology sector and globally distributed workforce. For instance, in 2025, Canadian architect Stephen Mauro did not realize that a North Korean remote IT worker had used a false identity to obtain employment with a third party and then misused Mauro’s professional credentials and seal. Other online researchers have revealed North Korean agents asking ChatGPT for Canadian civil engineering project codes. These examples illustrate how North Korea's IT worker schemes can exploit legitimate Canadian professional identities and employment relationships.
AI enables North Korea to circumvent previous limitations — such as limited overseas presence and language barriers — and Canada's response must account for this new reality. While traditional cybersecurity emphasized safeguarding online infrastructure through tools such as secure VPNs and password protections, AI-enabled cybercriminals are turning to social engineering — that is, the practice of obtaining confidential information by manipulation and phishing of legitimate users — to push the limits of how a fake identity can be forged. A convincing AI-generated email, work deliverables, and video conferences can exploit an employee without resorting to a software vulnerability.
Overall, AI makes it easier for malicious cyberactivity to take place. Previously isolated, technologically disadvantaged actors from North Korea can now conduct phishing, “vishing” (voice scams), and deepfake impersonation faster and more frequently, and even carry out consolidated attacks. Not only can it disrupt operations and create financial and regulatory losses for Canadian businesses and government organizations, but it can also erode public trust with attacks on broader civil society.
With AI-enhanced social engineering, North Korea is now able to rapidly scale its supply-chain attacks against open-source developers to potentially gain access to downstream software ecosystems. This year, for example, North Korea reportedly compromised axios, the popular open-source JavaScript library, demonstrating how malicious actors can exploit trusted developers to potentially reach millions of downstream users.
What’s Next
1. Alerting the Canadian public to Pyongyang’s cyber capabilities
The Canadian Centre for Cyber Security’s most recent assessment pays less attention to North Korea than to China, Russia, and Iran. Similarly, Canada's 2025 National Cyber Security Strategy should address key threats by name and tailor its cyber operation strategy accordingly, instead of taking a blanket approach and broadly calling out “malicious cyber actors.”
2. Canada’s cyber resilience should emphasize human, organizational vulnerabilities
Given the prevalence of small and medium enterprises that often lack the resources and organizational capacity to more thoroughly vet remote workers and contractors, Canada remains especially vulnerable to fraudulent North Korean IT workers using stolen identities or AI-generated personas.
3. Higher cybersecurity standards
To counter North Korea’s AI-boosted cybercrime more effectively, Canada needs to establish higher cybersecurity standards for its critical infrastructure, financial institutions, and third-party organizations handling sensitive government or research data, with priority given to phishing-resistant authentication and regular exercises simulating AI-enhanced attacks.
4. Indo-Pacific allies as information-sharing partners
There is an opportunity for Canada to expand information-sharing beyond its Five Eyes partners (Australia, New Zealand, the U.K., and the U.S.) and fellow NATO countries to include South Korea, Japan, and other Indo-Pacific partners. For example, South Korea dealt with North Korea’s massive, long-running cyberattacks on its military facilities in 2017 and its government institutions and thriving semiconductor industry in 2024. As a world leader in fundamental AI technology, Canada can shift from isolated-incident responses toward a more proactive, AI-assisted approach of hunting down vulnerabilities in its online financial system and cryptocurrency transactions before North Korean hackers reach them.
• Edited by: Erin Williams, Acting Vice-President, Research, and Ted Fraser, Senior Editor