Video
[Anchor]
New clues have been found to track the identity of the hacker who launched simultaneous cyberattacks on domestic financial institutions. A U.S. cybersecurity firm analyzed the server used in the attacks and secured AI conversation records, which reportedly contain personal information pointing to a "26-year-old Chinese national."
Reporter Choi Seung-hun has the details.
[Reporter]
This is the IP address suspected of being used in the successive attacks on domestic financial institutions.
U.S. cybersecurity firm CrowdStrike detected signs that "Artex," a Chinese-developed artificial intelligence penetration testing tool, was operating on a server utilizing this address.
The server contained instructions given to the AI in Chinese regarding hacking-related tasks, along with the IP address of another server located in Hong Kong.
Tracing this address led to conversation logs with "Claude Code," an AI-based programming tool, as well as configuration files for hacking programs.
This allowed investigators to peer into the conversations exchanged between the hacker and the AI.
The records included questions about where to trade information leaked from South Korea and how to find related Telegram groups.
However, another conversation revealed a request to "write a resume needed to apply for a security researcher position."
The information provided by the hacker to be included in the resume contained a name represented as "YY," a Chinese mobile phone number, a Telegram account, alongside a stated age of 26, residence in Guangdong Province, China, and an educational background from South China University of Technology.
This Telegram account appeared once more in the process of discussing another hacking attempt with Claude Code.
CrowdStrike raised the possibility that this information is linked to the attacker's identity.
However, it could not definitively confirm whether it belongs to the actual attacker, as the stated age and date of birth did not match each other.
[Hwang Seok-jin / Professor, Graduate School of Information Security, Dongguk University: I believe the technical analysis holds considerable reliability, but given that usage records and attack infrastructure have been secured, I think final verification by investigative authorities will be necessary....]
CrowdStrike analyzed that the attacker is not a skilled hacker, noting, "We do not believe they could have pulled off an attack of this scale alone without AI."
(Video editing: So Ji-hye, Design: Jeon Yu-geun)