News

Used Resume on Claude and Got Caught?… Clues Emerge on Suspected Financial Sector Hacker's Identity

The possibility has been raised that a person presumed to be behind the hacking attacks targeting South Korea's financial sector is a 26-year-old resident of Guangdong Province, China.

This marks the first time clues regarding the identity of the attacker in the recent financial hacking incident have been captured.

In an analytical report released on the 7th (local time), global cybersecurity firm CrowdStrike stated that the attacker is likely a 26-year-old individual residing in Guangdong Province, China.

However, the firm drew a line, explaining that this is a circumstantial estimation and not a definitive identification of the identity.

According to CrowdStrike, the clues were exposed while the individual suspected of being the attacker was using the generative AI coding tool "Claude Code."

The individual asked Claude to write a security researcher resume containing their penetration testing achievements, and in the process, personal information including their name initials, Telegram account, educational background, and place of residence was entered together.

It was revealed that the individual also asked Claude where stolen South Korean financial information is typically sold and how to find Korean-language Telegram data sales rooms.

The report stated that the same Telegram account was discovered in connection with other cyberattack circumstances as well.

Previously, CrowdStrike analyzed that attacks targeting South Korean financial institutions took place between the end of last month and early this month, and that the attacker utilized an open-source agentic penetration testing tool developed in China called "Artex" along with large language models.

According to this CrowdStrike analysis, the attacker used a two-tier server structure, using an IP address located in Hong Kong as the primary control infrastructure to direct the overall attacks, while operating the Artex servers actually used in the attacks against South Korea from a separate IP address.

It was analyzed that the attacker, presumed to be a Chinese speaker, may have acted out of financial motives.

Reported by Jung Da-eun | Video by Kihyun Kim | Design by Sumin Lee | Produced by SBS Digital News
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read