News

Instructed in Chinese, Targeting South Korean Financial Sector: How Was It Possible?

Instructed in Chinese, Targeting South Korean Financial Sector: How Was It Possible?
▲ ARTEX Korean Edition

Is it possible to find security vulnerabilities in South Korean financial institutions by giving instructions to artificial intelligence (AI) in Chinese?

"ARTEX," an AI penetration testing tool whose traces were recently identified in cyberattacks on the domestic financial sector, is a program that technically makes such operations possible.

It operates in a way where the AI does not just stop at finding security vulnerabilities, but establishes an inspection plan, executes tools, and even determines the next steps based on the results.

Because the technologies and communication rules used in web services do not vary significantly by country, and AI models capable of handling multiple languages can be utilized, South Korean services can be analyzed using only instructions in Chinese.

According to foreign media outlets such as Reuters, a Chinese security engineer using the handle "Autumn" released the tool on the developer platform GitHub this year.

The GitHub account name is "Autumn-27."

The name ARTEX is introduced in some introductory materials as an acronym for "Autonomous Red Team Expert."

In Korean, it is roughly translated as "autonomous mock attack expert."

A "Red Team" is understood to refer to a role that finds flaws in a security system from an attacker's perspective.

Penetration testing is a type of simulated hacking where security flaws are found like a hacker would, with permission from the system owner.

ARTEX itself is not an AI model like ChatGPT or Gemini.

It connects external large language models (LLMs) to utilize for decision-making and executes actual security tools based on those decisions.

In simple terms, it is a structure where the LLM acts as the "brain" and the inspection tools act as the "hands and feet."

The AI agent analyzes the target for inspection, establishes a plan, and then puts the tools into action.

It determines the next inspection direction based on the results, with multiple agents sharing roles such as planning and execution.

To use a home security inspection as an analogy, it is not merely advising to "check the window," but rather directly inspecting the window and then finding and selecting the next spot to examine.

The reason a Chinese-based tool can target South Korean financial institutions is analyzed to be because the AI agent understands the communication methods processed by computers.

Even if a webpage's guidance notice appears in Korean, the technologies and communication rules that constitute web services are commonly used across multiple countries.

This means that fluency in Korean is not strictly required to find technical weaknesses.

LLMs that process multiple languages can also be utilized to interpret Korean screens and phrases.

This explains why it is technically feasible to analyze Korean services while giving instructions in Chinese.

In fact, the US security firm CrowdStrike stated that it analyzed attacks targeting domestic financial institutions and confirmed AI instruction prompts written in Chinese as well as traces of ARTEX usage.

However, it evaluated the possibility that the attacker was a Chinese speaker with medium confidence and did not confirm their identity.

While the mere fact that Chinese-made tools were used cannot definitively conclude the attacker's nationality or the developer's involvement, it can provide important hints in understanding their traces and background.

The primary purpose of penetration testing is to find and fix weaknesses in security systems first.

However, the concern frequently raised is that the exact same functionality can also be used for unauthorized intrusions.

This means that AI can reduce the burden on security personnel while simultaneously becoming the hands and feet of attackers.

The recently released Korean version, "artex-ko," provides inspection results and reports in Korean.

The creator of the Korean version explains that the purpose of its release is to enhance defense and detection capabilities.

The Sigma and Suricata detection rules included here are "standard tables for finding suspicious traces" in system activity logs or network communications.

Sigma is a universal detection rule format for analyzing logs collected from various security products in a consistent manner.

The explanation is that the rules added to the Korean version are closer to a methodology that security personnel can utilize to detect ARTEX-related traces, rather than a function that unconditionally identifies ARTEX.

However, the specific background regarding why the developer of the Korean version separately added detection-related materials not present in the original has not been confirmed.

(Photo: Captured from GitHub, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read