
Logpresso links recent AI-backed cyberattacks on South Korean banks to a Chinese DDoS-for-hire group called GodNet.
A cybersecurity report by Logpresso links recent AI-backed cyberattacks on South Korean banks to a Chinese DDoS-for-hire group called GodNet, citing Telegram and GitHub records.
AI-generated summary
Logpresso analyzed a report by CrowdStrike regarding Telegram and GitHub records connected to infostealer malware.
A recent series of AI-backed cyberattacks on South Korean banks may be linked to a Chinese group that carries out distributed denial-of-service (DDoS) attacks for hire, according to a report released Sunday by a Seoul-based cybersecurity firm Logpresso.
The company said the Telegram account โYY520CN,โ linked to the bank hackings, was listed as a moderator of an online community called GodNet in September 2024. The community was created by Vitas, a Chinese group that carries out DDoS attacks for paying clients.
DDoS attacks flood websites or online services with traffic, overloading systems and preventing users from accessing them.
The findings by Logpresso stems from analysis of a report released earlier this month by US cybersecurity firm CrowdStrike, which compared Telegram and GitHub records with data stolen by malware known as an โinfostealer.โ The malware collects passwords and other login details from infected devices.
The Korean security firm also traced details of a second account on the GodNet staff list.
Logpresso examined GitHub code linked to that member and found a connection between a Telegram account and a GodNet domain name. It also found an email address in the codeโs edit history and traced it to login details stolen by infostealer malware in 2023.
The suspected member appeared to have been infected with password-stealing malware, exposing the accounts and services they used. The stolen data included login details for Microsoft and Oracle cloud services, suggesting that the member may have helped run the groupโs technical systems, according to Logpresso.
The second GodNet member has not been directly linked to the bank hacks, but Logpresso said investigators could identify the accountโs operator by comparing the stolen login data with cloud providersโ subscriber records, which could also help them trace the person behind YY520CN.
But the company said the account links alone do not establish who carried out the hacks, and it could not conclude that only one person was behind the breaches.
The identity of the YY520CN accountโs operator also remains unclear. CrowdStrike disclosed the Telegram username after examining AI-use records on a server linked to the attacks. The account was deleted on Oct. 8, after the report was released.
A new account later appeared under the same username, with a linked channel posting a denial of involvement. It remains unclear whether the same person controlled both accounts.
The owner of the phone number linked to YY520CN also denied involvement, saying someone had used their number without permission. Logpresso said it needed more information to verify the personโs identity.
South Korean authorities investigating the latest wave of cyberattacks suspect that the attacker combined multiple AI models, including DeepSeek, with ARTEX, a Chinese-made AI-powered penetration-testing tool. The attacker reportedly used Hong Kong-based control servers, separate attack servers and alternative access routes to target seven South Korean financial institutions in succession.
According to Reuters and other news outlets, ARTEXโs developer announced on GitHub that further updates and public distribution of the tool would be halted, citing its misuse in cyberattacks.
The developer, who goes by โAutumn-27โ on GitHub, said the tool would no longer be updated and would be switched to a closed-source model because of its misuse.
AI outlook โ possibilities, not facts
ARTEX developer to halt further updates and public distribution
Very likely ยท Within days

Apple Chairman Tim Cook visited China for the first time since leaving office as CEO, visited the 'iPhone 18 Pro' video filming site in Guangzhou, and attended an advisory meeting at Tsinghua University. At the same time, the investment amount of China's clean energy fund was doubled.

Seoul's historic Yongsan Electronics Market is set for a major overhaul to become an AI and ICT hub, with the first construction phase beginning this month as part of a plan to establish 'Asiaโs Silicon Valley.'

KAIST will hold the 'Physical AI Korea 2026' event at its headquarters in Daejeon on the 13th and announce its vision to foster it as a future industry by announcing physical AI platform technology applicable to robots, self-driving cars, etc. and research, education, and start-up strategies.

Counterpoint Research predicted that the demand for DRAM in the humanoid robot industry will increase approximately 20 times by 2030, and the average DRAM load per robot is expected to more than double from 19GB this year to 39GB in 2030. This is the result of a combination of increased memory capacity due to the advancement of AI models and expanded distribution of robots, and is emerging as a new growth engine for memory companies such as Samsung Electronics and SK Hynix.

LG U+ announced that it has collaborated with Solbit Systems to demonstrate technology that reduces the search range for mountain victims by approximately 99% from 706.86ใข to 4.13ใข by analyzing base station radio waves and mobile phone access records.

As personal information leaks continue to occur, the 'digital self-sufficiency' movement, in which citizens use AI to directly find their leaked information and request its deletion, is spreading. However, experts are warning that there is a risk of additional exposure when entering sensitive information into AI.