News

Financial Sector's 'AI Hacker' a 26-Year-Old Chinese National? 'Traces' Left Behind in AI

[Anchor]

New clues have been found to track the identity of the hacker who simultaneously attacked South Korean financial institutions. An American cybersecurity firm analyzed the server used in the attacks and secured AI chat logs, which contained personal information about a "26-year-old Chinese national."

Reporter Choi Seung-hun has the details.

[Reporter]

This is the IP address suspected of being used to launch consecutive attacks on domestic financial institutions.

American cybersecurity firm CrowdStrike detected signs that "Artext," a Chinese-developed AI penetration testing tool, was operated on a server using this IP address.

The server contained instructions in Chinese directing the AI to perform hacking-related tasks, along with the IP address of another server located in Hong Kong.

Tracing this address revealed chat logs with "Claude Code," an AI program used for coding, as well as configuration files for hacking programs.

This has made it possible to inspect the conversations exchanged between the hacker and the AI.

The logs included questions about where stolen information from South Korea is traded and how to find related Telegram groups.

However, another conversation revealed a request to "write a resume needed for applying as a security researcher."

The information the hacker provided to be included in the resume featured a name "YY," a Chinese mobile phone number, a Telegram account, an age of 26, residence in Guangdong Province, China, and an educational background from South China University of Technology.

This Telegram account appeared once more during discussions with Claude Code regarding another hacking incident.

CrowdStrike raised the possibility that this information is related to the attacker's identity.

However, they could not definitively conclude whether it belongs to the actual attacker, as the stated age and date of birth did not match each other.

[Hwang Seok-jin / Professor, Graduate School of Information Security, Dongguk University: While we consider the technical analysis to be quite reliable, and given that usage records and attack infrastructure have been secured, final verification by investigative authorities will likely be necessary.]

CrowdStrike analyzed that the attacker is not a skilled hacker, stating, "We do not believe they could have pulled off an attack of this scale alone without AI."

(Video editing: So Ji-hye, Design: Jeon Yu-geun)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read