[Anchor]
New clues have been found to track the identity of the hacker who launched simultaneous cyberattacks on domestic financial institutions. A U.S. cybersecurity firm analyzed the server used in the attacks and secured AI conversation records, which reportedly contain personal information pointing to a "26-year-old Chinese national."
Reporter Choi Seung-hun has the details.
[Reporter]
This is the IP address suspected of being used in the successive attacks on domestic financial institutions.
U.S. cybersecurity firm CrowdStrike detected signs that "Artex," a Chinese-developed artificial intelligence penetration testing tool, was operating on a server utilizing this address.
The server contained instructions given to the AI in Chinese regarding hacking-related tasks, along with the IP address of another server located in Hong Kong.
Tracing this address led to conversation logs with "Claude Code," an AI-based programming tool, as well as configuration files for hacking programs.
This allowed investigators to peer into the conversations exchanged between the hacker and the AI.
The records included questions about where to trade information leaked from South Korea and how to find related Telegram groups.
However, another conversation revealed a request to "write a resume needed to apply for a security researcher position."
The information provided by the hacker to be included in the resume contained a name represented as "YY," a Chinese mobile phone number, a Telegram account, alongside a stated age of 26, residence in Guangdong Province, China, and an educational background from South China University of Technology.
This Telegram account appeared once more in the process of discussing another hacking attempt with Claude Code.
CrowdStrike raised the possibility that this information is linked to the attacker's identity.
However, it could not definitively confirm whether it belongs to the actual attacker, as the stated age and date of birth did not match each other.
[Hwang Seok-jin / Professor, Graduate School of Information Security, Dongguk University: I believe the technical analysis holds considerable reliability, but given that usage records and attack infrastructure have been secured, I think final verification by investigative authorities will be necessary....]
CrowdStrike analyzed that the attacker is not a skilled hacker, noting, "We do not believe they could have pulled off an attack of this scale alone without AI."
(Video editing: So Ji-hye, Design: Jeon Yu-geun)
※ Please note: This article was translated by AI and may contain errors.
Financial Sector's 'AI Hacker' a 26-Year-Old Chinese National? Clues Left in AI Chat Logs
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.
Trending Now
-
Video News
"It Was the Home Where I Lived All My Life"... Elderly Woman Evicted on a Stretcher Passes Away
-
Video News
Former National Football Player Reported for Retaliatory Driving in "Terror SUV"
-
Video News
"Sudden Exploding Sounds"... Man Found Dead on First Floor of Building
-
Video News
Few Footprints or Fingerprints Left... Naju Couple Murder Suspect Breaks Silence
-
Video News
"Save Me": Note Thrown From Behind Bars as 4 Patients Die Consecutively
Video News
Video News
Video News
Video News
Video News