A foreign security firm’s analysis revealed that clues estimating the identity of the attacker behind hacking attacks targeting South Korean financial companies have been discovered. Personal information entered by the attacker while requesting an AI to create a resume became the clue. However, it has not been confirmed whether the information is that of the actual attacker.

U.S. cybersecurity firm CrowdStrike stated in a report released on the 7th (local time) that they analyzed files accessible to outsiders on servers used by the attacker to execute attack tools. They secured conversation records from the AI coding tool ‘Claude Code’ and configuration files from the security inspection tool ‘ARTEX (ARTEX)’, among others, and explained that through this, they confirmed attack activities targeting South Korean financial institutions.
The attacker requested the creation of a security researcher’s resume on Claude Code, including achievements related to ARTEX. ARTEX is a tool developed in China, used to find security vulnerabilities by simulating attacks on systems. The request included the name ‘YY’, Telegram account ‘@YY520CN’, educational background ‘South China University of Technology’, residence ‘Maoming City, Guangdong Province, China’, and others. The age was entered as 26, but the initially input date of birth, September 22, 2007, did not match the age.
The same Telegram account name appeared in Claude Code conversation records where security vulnerabilities were being sought in a Telegram-based NFT (non-fungible token) futures trading service. The same account name was also used in circumstances where a presumed Chinese payment service was attacked. The report also included content where the attacker asked Claude Code for places to sell leaked South Korean information and requested finding Telegram groups for selling South Korean data.
The servers and AI models used in the attack were also analyzed. The attacker used a server in Hong Kong as a main base and executed ARTEX, presumed to have been used in attacks on South Korean financial institutions, on a separate server. Additionally, it was found that nine proxy IPs (Internet addresses) were used to relay connections.
The primary AI model driving ARTEX was DeepSeek’s ‘v4.1-flash’. Additionally, Claude Code utilized ‘GLM-5.3’ and ‘Grok 4.6’ from Chinese Z.ai. CrowdStrike also suggested the possibility that the attacker accessed DeepSeek through a brokerage or resale company that intermediates AI model access.
CrowdStrike analyzed that the attacker is likely a Chinese speaker seeking financial gain, based on Chinese request texts and circumstances of ARTEX use. They rated the reliability of this judgment as ‘moderate’. While they considered it highly possible that the personal information entered in the resume belongs to the attacker, they stated, “The currently secured information alone cannot definitively link this personal information to the attacker.”

CrowdStrike, established in 2011 and listed on the U.S. Nasdaq in 2019, is a security specialist company. It provides services to detect and respond to intrusions in corporate PCs, servers, and clouds, and threat intelligence analysis tracking attackers’ activities is also a key business. According to corporate introduction materials published by Nasdaq, they participated in the investigation of the 2016 hacking incident targeting the U.S. Democratic National Committee.





Leave a comment