SK Shields Financial Hacking Report
Attacks from the Outside, Not the Key System
Attackers are estimated to be 26 years old living in Guangdong Province
The hacker who recently attacked the domestic financial sector may be a 26-year-old man living in Guangdong Province, China, according to an analysis. Personal information entered by the attacker to write a resume on an artificial intelligence (AI) coding tool became a clue. It is analyzed that he dug into the loopholes of the external system of financial companies with an automated tool for AI hacking made in China.
In a report released by global cybersecurity firm CrowdStrike on the 7th (local time), it said, “The attacker asked Antropic’s ‘Claude Code’ for a security researcher’s resume and asked them to include the results of the attack against Korean financial companies as a career.” In the process, the initials of the English name, phone number, Telegram account, academic background (Huanan University of Technology), and residence (Mao Ming, Guangdong Province) were entered together. However, according to the first date of birth, he was born in 2007, which does not match the age he wrote. CrowdStrike said, “It is likely that the information belongs to the attacker himself, but we cannot identify him.”
◆ Expose personal information in attacker public folder
The personal clue came from a server managed by the attacker. CrowdStrike secured Claude code job records, memory files, and hacking tool setting files from the server’s public folder, which was open for anyone to see without authentication. This is the result of tracking the Hong Kong Internet Protocol (IP) written on the server’s document related to the penetration of Korean financial companies. CrowdStrike analyzed, “It is a dual structure in which Hong Kong servers serve as the main base, and a separate server is believed to have carried out attacks in Korea.” In the work record, there was also a request to find a Telegram group that mainly sells related information and asks where the leaked data is traded in Korea.
ARTEX, an open-source agent penetration test tool developed in China, was used to break into Korean financial companies. It is a program that automates AI to find vulnerabilities and even attempt attacks on its own. Artex, operated by the attacker, used China’s DeepSeek’s “V4.1-Flash” as its main model. China’s ZpuAI’s GLM-5.3 and U.S. SpaceXAI’s “Grook 4.6” were also used as assistants for some of the Claude Code work. CrowdStrike estimated the attacker to be a financially motivated Chinese speaker.
◆ It’s not a core system. It’s a hole in the outside
Analysts said that if the hacker’s personal information was revealed on the server, the reason why the financial company was breached was also a gap in basic security. In a report released on the 8th, SK Shields defined the incident as “an attack that penetrated loopholes in external systems neglected by financial companies at the speed of machines, not a hack that created new vulnerabilities by AI.”
SK Shields also took a look at how Artex works. When the AI agent in charge of planning determines the next action, several execution agents simultaneously check and share the results for each target and path. The planning agent redetermines the response direction based on the derived results and repeats the check. SK Shields explained, “This structure can reduce the burden of attackers’ step-by-step intervention and increase the speed and range of attacks.”
The infringement route was an externally exposed work assistance system, such as inquiring loan recruiters and supporting employee work, and damage to the core financial transaction system was not confirmed.
Adam Myers, general manager of CrowdStrike attack response operations, analyzed, “Hackers are evolving in the direction of speeding up and scaling up attacks by combining agentic AI tools and existing attack techniques.”
Click Here For The Original Source.
