Video
[Anchor]
New clues have been found to track the identity of hackers who simultaneously attacked domestic financial institutions. A U.S. cybersecurity firm analyzed the servers used in the attack and secured AI chat logs, which contained the personal information of a "26-year-old Chinese national."
Reporter Choi Seung-hun has the story.
[Reporter]
This is the IP address suspected of being used in consecutive attacks on domestic financial institutions.
U.S. cybersecurity firm CrowdStrike captured signs that "Artex," an AI penetration testing tool developed in China, was operated on a server using this IP address.
The server contained instructions in Chinese directing the AI to perform hacking-related tasks, along with the IP address of another server located in Hong Kong.
Following this address left chat logs with "Claude Code," an AI program used to write programs, as well as hacking program configuration files.
This made it possible to look into the conversations the hacker exchanged with the AI.
There were also questions asking where to trade information leaked from Korea and how to find related Telegram groups.
However, another conversation revealed a request to "write a resume necessary for supporting a security researcher."
The information the hacker provided to be included in the resume contained the name "YY," a Chinese mobile phone number, a Telegram account, along with the age of 26, residence in Guangdong Province, China, and an educational background from South China University of Technology.
This Telegram account appeared once more in the process of discussing Claude Code and another hack.
CrowdStrike raised the possibility that this information could be related to the attacker's identity.
However, they could not conclude whether it was the actual attacker's identity, as the stated age and date of birth did not match each other.
[Hwang Seok-jin / Professor, Graduate School of Information Security, Dongguk University: I think the technical analysis holds a considerable level of reliability, but since usage records and attack infrastructure have been secured to some extent, final verification by investigative authorities seems necessary....]
CrowdStrike analyzed that the attacker is not a skilled hacker and stated, "We do not believe they carried out an attack of this scale alone without AI."
(Video Editing: So Ji-hye, Design: Jeon Yu-geun)
---
[Anchor]
Then who is the person pointed to by these clues? Our reporting team contacted the Chinese mobile phone number and Telegram account remaining in the report. This individual denied involvement in the hacking and claimed that their information had been stolen.
Reporter Choi Seung-hun continues the coverage.
[Reporter]
This is the Chinese mobile phone number that appeared in the CrowdStrike report.
When SBS reporters called directly, a man presumed to be Chinese answered.
[Chinese phone number recipient: I'm not a hacker. What are you talking about? Is this a scam call?]
While the report stated that the suspected hacker attended South China University of Technology, a prestigious Chinese university, the person on the call said they dropped out of school.
[Chinese phone number recipient: I dropped out of school. (Aren't you a software engineer?) No, I'm not.]
Contrary to the report's content that he resides in Maoming, Guangdong Province, the person on the call said he was in the Hunan Province region, some 900 kilometers away.
[Chinese phone number recipient: I'm in Changsha (Hunan Province). Changsha. I'm in Changsha.]
This time, a message was sent to the Telegram account "YY" listed in库 the report.
The account operator responded that while they do use that account, the phone number written in the report is not theirs.
Their residence was stated as Zhengzhou, Henan Province, neither Guangdong Province as stated in the report nor Hunan Province where the phone number user is located.
They claimed that someone stole their personal information and suspected someone they recently had a conflict with.
They added, "I hope the South Korean side investigates thoroughly and does not involve me."
Afterwards, the Telegram account was deleted.
The account could also be found in a notice on a Chinese-language Telegram community.
It was a community related to DDoS attacks, which paralyze services through mass access attempts, and this account was registered as an operations management person in charge.
However, there is also a possibility that the hacker left the information of an unrelated person online to evade tracking.
Police explained that while this identity-related information is an investigative clue that requires verification, they are pursuing all possibilities, including the attacker's nationality, active region, and whether it was a solo crime.
(Video Editing: Park Na-young, VJ: Lee Ji-hwan, Design: Park Cheon-ung)