SEOUL, Oct 8 (Reuters) – The suspect behind recent cyberattacks targeting South Korea’s financial sector may be a 26-year-old based in China’s Guangdong province, US cybersecurity firm CrowdStrike said.
In a report published on its website on Wednesday, CrowdStrike said it uncovered personal details linked to the suspected attacker while analysing AI coding-tool sessions and infrastructure associated with a campaign targeting South Korean financial institutions from late September to early October.
CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside large language models and assessed with “moderate confidence” that the actor was a Chinese speaker and likely financially motivated.
The firm said one Claude Code session contained a request to create a security researcher resume describing results from the hacking activity.
The prompt included details such as a Telegram account, age, education background and a location in Maoming, Guangdong, the report said.
CrowdStrike said the same Telegram username appeared in other cyber activity, including vulnerability research involving a Telegram-based NFT marketplace and a separate suspected attack on a Chinese payment platform.
The company said the personal details likely belonged to the actor responsible for the activity, but cautioned that currently available information could not definitively identify the attacker.
Authorities in Seoul are investigating cyberattacks that affected multiple financial institutions after banks including Shinhan Bank and KB Kookmin Bank reported data breaches.
South Korean police, who have launched a probe, did not immediately respond to a request for comment.
South Korean President Lee Jae Myung said on Tuesday that signs had emerged that AI was used in some of the hacking incidents and called for heightened cybersecurity measures.
(Reporting by Kyu-seok Shim; Editing by Chris Reese and Ed Davies)


Comments