
It has been suggested that the perpetrator of the recent large-scale hacking attack targeting South Korea's financial sector may be a 26-year-old individual residing in Guangdong Province, China. The hacker left information presumed to be their identity while requesting an AI to write a resume. In particular, it was revealed that the hacker even inquired with the AI about channels through which they could sell stolen Korean personal data, increasing the likelihood that the attack was motivated by financial gain. Concerns are also rising over secondary damage, such as the leaked personal information being exploited for additional crimes like voice phishing.
According to the financial sector on the 8th, U.S. cybersecurity firm CrowdStrike discovered specific clues allowing for an estimation of the hacker's identity in a report released the previous day titled "Unknown attacker used AI-based ARTEX to attack South Korea's financial sector."
CrowdStrike confirmed this information while analyzing work records from the AI coding tool 'Claude Code' that remained on the server used by the hacker. The hacker requested Claude Code to write a resume for a security researcher, instructing it to include penetration testing results utilizing ARTEX.
In the process, the hacker listed their name as 'YY' and age as 26. They entered their educational background as South China University of Technology and their residence as Maoming, Guangdong Province, China. A Chinese phone number and Telegram account '@YY520CN' were also left behind. However, the date of birth initially entered was September 22, 2007, which did not match the stated age of 26.
Considering that ARTEX, developed in China, was used and commands were given to the AI in Chinese, it was suggested that the hacker may be a Chinese speaker. However, CrowdStrike explained that with the materials currently secured, it is not possible to definitively determine the specific country, hacking organization, or identity responsible.
The relevant Telegram account was also discovered in other cyber attack circumstances. According to CrowdStrike, the same account name was used in Claude Code work records investigating vulnerabilities in a Telegram-based non-fungible token (NFT) futures trading platform. The same account was also confirmed in an attack presumed to target a Chinese payment platform.
Furthermore, CrowdStrike assessed that this attacker likely acted based on financial motives. The Claude Code work records secured by CrowdStrike included content where the hacker asked where stolen Korean personal information is typically sold. There was also a request to find Telegram groups trading Korean personal data. It has not been confirmed whether actual sales of personal information took place.
A senior official related to financial sector security stated, "The content of CrowdStrike's report itself is highly likely to be accurate," while adding, "However, if the hacker recorded false information, it could be incorrect." He continued, "The issue is that such attacks are happening more frequently, and because the financial motive is significant, the possibility of secondary damage is high."