News

Financial Sector's 'AI Hacker' Chinese? Traces Left in AI

[Anchor]

New traces left by hackers who simultaneously attacked the financial sector have been discovered. An American cybersecurity firm secured records of a hacker conversing with AI on a server used in the attacks, which revealed the personal information of a 26-year-old Chinese national.

Reporter Choi Seung-hun reports in sequence.

[Reporter]

This is the IP address suspected of being used to successively attack domestic financial institutions.

US cybersecurity firm CrowdStrike detected circumstances indicating that an AI penetration testing tool developed in China, named Artext, was operated on a server using this IP address.

On the server, along with instructions given to the AI in Chinese regarding hacking-related tasks, the IP address of another server located in Hong Kong was written down.

Following this address revealed conversation records with Claude Code, a program that writes code using AI, as well as configuration files for hacking programs.

This made it possible to look into the conversations exchanged between the hacker and the AI.

There were also inquiries asking where information leaked from South Korea is traded and how to find related Telegram groups.

However, another conversation contained a request to "write a resume needed to apply for a security researcher position."

The information the hacker provided to be included in the resume contained a name, a Chinese mobile phone number, a Telegram account, along with an age of 26, residence in Guangdong Province, China, and an educational background from South China University of Technology.

This Telegram account appeared once more during the process of discussing Claude Code and another hacking attempt.

CrowdStrike raised the possibility that this information is related to the attacker's identity.

However, they could not definitively conclude whether it is the actual attacker's identity, as the listed age and date of birth did not match each other.

[Hwang Seok-jin / Professor, Dongguk University Graduate School of Information Security: I judge that the technical analysis has considerable reliability, but given that usage records and attack infrastructure have been secured, final verification by investigative agencies seems necessary....]

CrowdStrike analyzed that the attacker is not a skilled hacker and stated, "We do not believe they could have pulled off an attack of this scale alone without AI."

(Video Editing: So Ji-hye, Design: Jeon Yu-geun)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read