APT Operations Against AI Systems
2026-05-14 • Krypt3ia •
Krypt3ia assesses that enterprise AI systems are becoming high-value operational infrastructure because they ingest sensitive data, connect to internal workflows, and increasingly act with delegated authority. The North Korea-focused section argues that DPRK operations are likely to target financially valuable AI ecosystems and identity-centric workflows, consistent with cryptocurrency theft, remote employment fraud, synthetic identity activity, and scalable deception. The report highlights likely abuse of AI-driven recruiting, developer-assistance, fraud-detection, and financial AI systems to support access generation and cryptocurrency theft. It frames these risks alongside prompt injection, retrieval poisoning, model theft, AI supply-chain compromise, and agentic workflow abuse as emerging attack surfaces for state-backed actors.