Financial Sector Hackers Switched AI Models in Attacks, Even Asked Where to Sell Stolen Data
IT DAILY ·
✦ AI Summary
CrowdStrike said in a report released on July 7 on recent attacks targeting South Korean financial institutions that the group behind hacking attempts in the domestic financial sector appeared to have used multiple AI models in combination with tools.
The report said the attacker asked Claude to draft a resume for a security researcher that included ARTEX-related activity, and also inquired about places to sell stolen data and searches for related Telegram sales groups.
Financial authorities identified common attack IPs and similar tactics across incidents at several financial firms, while the Financial Supervisory Service shared 28 duplicate-free hacking attempt IPs and ordered about 500 financial firms to block them and check for breaches.
CrowdStrike released a report on July 7, local time, analyzing recent attacks targeting South Korean financial institutions. The report said it found signs that the group behind hacking attempts against the domestic financial sector used multiple AI models in combination with tools.
The report included signs that AI was used in penetration efforts. It said evidence showed the attacker had tried to use AI during the attack phase.
In particular, the report confirmed the attacker used Claude. The attacker was found to have asked Claude to draft a resume for a security researcher that included work related to 'ARTEX.'
It also found records of questions about where to sell stolen data, confirming signs that AI was being used not only in the attack phase but also in the criminal monetization process. ARTEX is a China-made AI-based autonomous penetration testing tool, and it has recently been identified as a tool used in hacking incidents targeting the financial sector.
The personal information included in the request listed a residence in Maoming, Guangdong Province, China, and an age of 26, but the date of birth given alongside it was September 22, 2007, so the age and birth date did not match.
CrowdStrike said it tracked the related attack activity based on past use of the Telegram account 'YY520CN' by the attacker. CrowdStrike said the account had previously been used for analyzing vulnerabilities in an NFT marketplace and was also believed to have been used in an attack on a payment platform in China.
However, CrowdStrike said it was impossible to establish a definitive link to the attacker's real identity. CrowdStrike said the personal information in the messages was likely that of the attacker who carried out ARTEX-related activity, but added that no firm connection between that information and the attacker could be confirmed at this point. It also said the attacker used Chinese and that the motive was likely financial.
The report also analyzed the infrastructure used by the hacker. CrowdStrike said it identified overlapping IP addresses in this hacking case, and that the attacker was hosting an ARTEX instance on those IPs. The attacker was also operating a public directory on the IP that included a Claude code markdown document, and that markdown document contained Chinese instructions on how to use an LLM to carry out penetration testing.
It also said there was a Hong Kong-based IP address controlled by the hacker, and CrowdStrike conducted further analysis of that Hong Kong-based IP. The additional analysis uncovered Claude code session logs and ARTEX configuration files. The IP address in Hong Kong appeared to serve as the main infrastructure managed by the attacker.
The report also identified the LLMs used in the ARTEX attack. DeepSeek v4.1 Flash was used as the main LLM in the ARTEX attack, and the hacker also used Z.ai's 'GLM 5.3' and 'Grok 4.6.'
Signs were also confirmed that the hacker asked Claude, the AI tool, about places in South Korea where stolen data could be sold, and requested searches for related Telegram sales groups, but the number of victim institutions has not yet been finalized.
The financial institutions for which personal data breaches have already been confirmed are Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram, Welcome Savings Bank, and Hyundai Capital, a total of 7 companies. Financial authorities identified common attack IPs across incidents involving several financial firms and also detected similar tactics. Accordingly, the authorities are treating the same attacker as a working hypothesis and are investigating the possibility of large-scale automated attacks using AI tools while switching IPs.
Accordingly, the Financial Supervisory Service shared 28 duplicate-free hacking attempt IPs with the financial sector as of the 6th, and also shared information on security vulnerabilities. It also ordered about 500 financial firms to block the attack IPs and check for breaches, and instructed them to inspect externally exposed IT assets and service vulnerabilities. The Financial Supervisory Service expanded the scope of its response to the entire financial sector.
Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=242082
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.