
The person identified as the mastermind behind the hack targeting the financial sector captured the activities of the community supervisor of the Chinese DDoS agency 'Godnet and Vitas'.
Domestic security company Logpresso announced that it had confirmed that the Chinese suspect 'YY520CN', who was identified as the mastermind behind the financial sector hacking attack, was active as a community supervisor for the Chinese DDoS agency 'Godnet/Vitas'.
AI-generated summary
Amid concerns raised about the connection between hacking attacks targeting the domestic financial sector and Chinese DDoS agency organizations, security companies are disclosing their analysis results.
Domestic security company Logpresso discloses information collection and cross-analysis results
Financial hacking suspect 'YY520CN', traces of DDoS organization supervisor activity
(Seoul = Yonhap News) Reporter Hayoung Kwon = The possibility has been raised that the person identified as the mastermind behind the hacking attack targeting the domestic financial sector is a member of a Chinese DDoS (distributed denial of service) agency.
According to the results of 'Additional Analysis of the ARTEX Campaign - Verification of the Attack Group' published by domestic security company Logpresso on the 9th, the US security company CrowdStrike confirmed that a specific suspect was active in the Chinese DDoS agency hacking organization 'GodNet and VITAS'.
Previously, CrowdStrike analyzed that in attacks targeting Korean financial institutions from late last month to early this month, attackers used Chinese artificial intelligence (AI) penetration testing tool 'ARTEX' and AI models such as DeepSeek.
In addition, it was revealed that personal information such as name initials, Telegram account, and residence were exposed when the attacker requested a security researcher's resume using the AI coding tool 'Claude Code', raising the possibility that he was a 26-year-old person living in Guangdong Province, China.
However, the Chinese suspect identified at the time, 'YY520CN', reportedly stated that his mobile phone number had been stolen and that he had nothing to do with the hacking.
Logpresso obtained additional clues by cross-analyzing authentication information leaked to Telegram, GitHub, and the dark web, and the analysis revealed that the YY520CN account was active in the position of 'community supervisor', which manages members in the Godnet and Vitas organizations.
Godnet and Vitas are Chinese hacking organizations that carry out DDoS attacks. It was discovered that they operated a community on Telegram called ‘Sangje Society’ and divided the organization into top administrators, community managers, supervisors, applicants, advertisers, etc.
The 'HangHang2017' account, a member of the same organization, was found to have been infected with 'Inpostealer', a malware that secretly steals website login information from terminals in 2023, leaving numerous traces.
Logpresso said that based on this information, it had secured the email address and domain associated with the HangHang2017 account. The explanation is that related indicators were found by sequentially comparing GitHub commits (records) that record the developer's source code modification history, the Telegram organization member list, and authentication information leaked through Infostealer (malware).
By comparing the email and domain information obtained in this way with the cloud provider's subscription information, the actual operator of the HangHang2017 account can be confirmed, and it is expected that the identity of YY520CN can be cross-verified using this as a starting point.
Logpresso advised that all systems that can be accessed from outside, even if they are not customer services, should be included in the inspection target. He added that it is necessary to check whether the viewing permissions after logging in are properly set and whether abnormally repeated viewing behavior is detected.

Coupang's shopping, food delivery, and streaming platforms experienced service disruptions around midnight due to an error during a service upgrade, affecting over 30 million monthly active users; access was restored by 2:30 a.m. after login and logistics issues persisted briefly.

Open AI's annualized sales were confirmed to be $50 billion, $20 billion less than the initially announced $70 billion, shocking the market, and this is believed to be due to differences in sales calculation methods.

President Trump will award the most prestigious medal in the field of science and technology to IT entrepreneurs including Musk, Jensen Huang, Lisa Su, and Sergey Brin at the White House. Fox News reported this as an example showing that the relationship between Musk and Trump has fully recovered.

CrowdStrike announced that it had discovered for the first time clues regarding the identity of the person believed to be behind a hacking attack targeting the Korean financial sector. It was estimated that the attacker may be a 26-year-old living in Guangdong Province, China, but it was determined that the identity of the attacker was not conclusive. The clue came from a request to write a resume for a security researcher exposed while using the generative AI coding tool 'Claude Code', and it was analyzed that personal information such as a Telegram account was entered.

Of the 119 AI chatbot reports related to sexual exploitation of children and adolescents and obscene and lascivious content received by the Korea Media and Communications Standards Commission, 76 are being reviewed by the Secretariat. Of these, 43 cases have passed 180 days since receipt and 7 cases have exceeded a year. Rep. Kim Seon-min called for a deadline for processing and information on the reasons for delays in long-term unprocessed complaints.

Open AI shocked the mathematics world by revealing new solutions to over 300 mathematical problems in various fields, including algebra and mathematical logic. Progress on three Millennium Prize problems, including proof of the Jun-Riemann hypothesis, is also included, and mathematicians are shaken by the challenge of AI.