News

Finding Vulnerabilities and Attacking Fast: How to Stop 'AI Hacking'

[Anchor]

Circumstances suggest that the recent hacking incidents utilized AI capable of autonomously analyzing and identifying vulnerabilities in security systems. Experts point out that as attack methods grow more sophisticated, defense strategies must also be overhauled.

Reporter Hong Yeongjae has the details.

[Reporter]

This is an AI tool called "Artex," which was uploaded to a platform where developers share code and work tasks.

The description in Chinese introduces it as an "autonomous AI penetration testing system."

It is an AI program originally developed to perform simulated hacking by autonomously finding system vulnerabilities.

A domestic security company stated that upon analyzing a server web page suspected of being used in the recent financial sector cyberattack, phrases matching "Artex" were found among the traces of the attack.

[Moon Jong-hyun / Director, Genians Security Center: If someone uses this not for actual penetration testing but for an attack, it is a tool with significant impact, to the extent that it can be deployed immediately for real-world attacks.]

More precise investigations are still needed to confirm whether AI tools like Artex were actually utilized in the hacking.

However, the government acknowledged the possibility because the attacks involved large-scale, automated assaults carried out simultaneously against multiple financial institutions.

The greatest advantage of utilizing AI tools as hacking weapons is speed.

AI can identify internet-connected equipment, software types, and vulnerabilities in a short period—tasks that hackers previously had to search for manually.

Experts point out that comprehensive inspections must be conducted not only on core financial network systems, which have relatively high security levels, but also on areas that have previously slipped down the management priority list, such as employee mobile devices and external systems used by loan recruiters.

[Kim Seung-joo / Professor, Graduate School of Information Security, Korea University: Conducting a complete asset inventory—figuring out exactly how many PCs we have, what operating systems and software are installed on them, and how many of them are connected to the internet—is the most urgent task.]

They also advise that countermeasures should not stop at blocking a single AI tool, given that various AI hacking tools other than Artex are already publicly available and that hacking capabilities will likely improve further as AI models become more advanced.

(Video by: Kim Seung-tae | Video Editing by: Lee So-young | Graphics by: Im Chan-hyuk)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read