Clues regarding the identity of the person suspected to be behind recent cyberattacks targeting South Korea's financial sector have been captured for the first time.
In an analysis report released on October 7 (local time), global cybersecurity firm CrowdStrike stated that the attacker is likely a 26-year-old individual residing in Guangdong Province, China.
However, the company drew a line, explaining that this is an estimation based on circumstantial evidence and does not constitute a definitive identification.
According to CrowdStrike, these clues were exposed while the attacker was using the generative artificial intelligence (AI) coding tool Claude Code.
The attacker asked Claude to write a security researcher resume containing their penetration testing achievements, and personal information including their name initials, Telegram account, educational background, and place of residence was entered in the process.
The report stated that the Telegram account in question was also found under identical circumstances in other cyberattack contexts.
It was identified that the same account name was used in a session investigating vulnerabilities in a Telegram-based non-fungible token (NFT) futures marketplace and in circumstances pointing to an attack targeting a Chinese payment platform.
While suggesting the possibility that it is the same individual based on these intersecting circumstances, CrowdStrike added that the identity cannot be definitively concluded with the information secured thus far.
Previously, CrowdStrike analyzed that attacks targeting South Korean financial institutions took place between the end of last month and early this month, and that the attacker utilized an open-source agentic penetration testing tool developed in China called ARTEX alongside a large language model (LLM).
The attacker, presumed to be a Chinese-language user, was assessed with medium confidence to have likely been motivated by financial incentives.