概要: Geniansは、北朝鮮のKimsukyグループがAIで生成されたとされるディープフェイク軍人身分証明書を使用したフィッシング攻撃を報告しました。韓国の防衛機関を装ったとされるメールには、偽造IDが添付されたZIPファイルが添付されており、その写真は生成AIによって作成されたとされています。開封すると、隠されたマルウェアが実行され、Hancom Officeのアップデートを装ったスクリプトがダウンロードされたと報告されています。これは、AIデコイを用いてソーシャルエンジニアリングを強化するKimsukyの戦術の進化を示すものとされています。
Editor Notes: Timeline notes: 07/17/2025 is when Genians reportedly "detected a spear-phishing attack attributed to the Kimsuky group. This was classified as an APT attack impersonating a South Korean defense-related institution, disguised as if it were handling ID issuance tasks for military-affiliated officials. The threat actor used ChatGPT, a generative AI, to produce sample ID card images, which were then leveraged in the attack. This is a real case demonstrating the Kimsuky group's application of deepfake technology." The full report contains further details with date-stamped files ranging between 2018 to 2025. The report was published online on 09/14/2025, with press reports being published the following day. Read the full Genians report in English here: https://www.genians.co.kr/en/blog/threat_intelligence/deepfake. Read the report in Korean here: https://www.genians.co.kr/blog/threat_intelligence/deepfake?hs_preview=uBKeAJml-237330098891&hsCtaAttrib=238054141679.
Alleged: OpenAI developed an AI system deployed by Velvet Chollima , THALLIUM , Reconnaissance General Bureau , Kimsuky Group , Group 0094 , Emerald Sleet , Black Banshee , APT43 と Government of North Korea, which harmed Truth , South Korean defense personnel , National security and intelligence stakeholders , Government of South Korea , General public of South Korea と Epistemic integrity.
関与が疑われるAIシステム: Hancom Office と ChatGPT
インシデントのステータス
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
4.3. Fraud, scams, and targeted manipulation
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Malicious Actors & Misuse
Entity
Which, if any, entity is presented as the main cause of the risk
Human
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Post-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Intentional
インシデントレポート
レポートタイムライン
Loading...