
중국에서 개발된 오픈소스 사이버 보안 도구 ARTEX가 한국 금융사 해킹에 악용된 정황이 월스트리트저널 보도를 통해 드러났다. 해커들은 이 도구를 이용해 여러 AI 모델을 동원한 보안 공격을 감행했으며, 공격은 미국, 일본, 독일 등 10여 개국을 경유해 실행됐다. 개발자는 악용 방지를 위한 이용자 지침을 명시했으나 실효성은 제한적이라는 지적이 나왔다.
AI-generated summary
중국에서 개발된 오픈소스 사이버 보안 도구 ARTEX는 원래 네트워크 취약점 파악을 돕기 위한 목적으로 만들어졌으나, 해커들이 이를 악용해 한국 금융사를 대상으로 한 보안 공격을 감행한 것으로 보인다.
(샌프란시스코=연합뉴스) 권영전 특파원 = 한국 금융사들을 해킹하는 데 쓰였다는 정황이 드러난 'ARTEX AI'는 중국에서 개발된 사이버 보안 도구이지만, 해커들은 이를 악용해 은행을 공격한 것으로 보인다고 월스트리트저널(WSJ)이 보도했다.
WSJ은 6일(현지시간) 중국의 개방형(오픈소스) 사이버 보안도구 ARTEX를 조명했다.
ARTEX는 '오텀'(Autumn)이라는 별명을 사용하는 중국의 사이버 보안 엔지니어 리푸화(Li Puhua)가 개발한 개방형 AI 에이전트다.
이 에이전트는 그 자체로는 인공지능(AI) 모델이 아니지만, 이 도구를 이용하면 다른 여러 AI 모델을 불러와서 마치 팀원처럼 활용할 수 있다.
예를 들어 앤트로픽의 클로드나 오픈AI의 GPT, 중국의 AI 모델 딥시크 등을 불러와서 ARTEX 상에서 사용하는 방식이다.
개발자는 원래 여러 기관이 네트워크 취약점을 파악할 수 있도록 돕기 위한 사이버 보안 용도로 이 도구를 만들었지만, 해커들은 도리어 이를 악용해 AI 모델을 이용한 보안 공격을 감행한 것으로 보인다.
이 같은 악용이 가능했던 것은 해당 도구가 개방형으로 공개돼 누구나 무료로 내려받아 각자의 목적에 맞게 고쳐서 사용할 수 있었기 때문이다.
ARTEX는 은행 해킹 사건이 보도된 이후 무단 사이버 침입이나 데이터 훔치기 등 악의적 목적으로 사용해선 안 된다고 이용자 지침에 명시했다.
그러나 이는 선언적인 조치일 뿐으로, 범죄를 저지르려는 이용자가 사이버 공격 등에 악용하는 것을 원천적으로 막을 수 있는 수단은 아니다.
한국의 사이버보안 분석기업 지니언스시큐리티센터의 문종현 센터장은 "한국에서 AI 에이전트를 활용한 사이버 보안 공격이 증가하고 있다"며 "전 세계적으로도 그 수가 늘어날 것으로 예상된다"고 말했다.
ARTEX는 지난달 중국에서 개최된 사이버 보안 공격·방어용 에이전트형 AI 시스템 대회에서 우승하며 주목받은 바 있다.
이번 한국 금융사 공격은 추적을 피하기 위해 미국과 일본, 독일 등 10여 개국 20여 개의 IP 주소를 거쳐 실행됐다.
용의자 신원은 아직 특정되지 않았으나, 공격에 활용된 웹서버 일부에서 'ARTEX-自主渗透試控制台'라는 중국어 문자열이 확인됐다.
AI outlook — possibilities, not facts
한국에서 AI 에이전트를 활용한 사이버 보안 공격이 증가할 것으로 예상된다
Likely · Within months

It was confirmed through analysis by security company Oasis Security that two large domestic churches suffered cyber attacks and a large amount of data, including personal information of members, donation records, and internal documents, was leaked. It is analyzed that the attacker used a web shell and account information to infiltrate the internal system.

Over the past five years, the share of major overseas telecommunications carriers, such as Google and Netflix, in domestic Internet traffic has increased to 47%. As foreign operators took the top 1 to 3 positions, the debate over network usage fees reignited.

Minister of Science and ICT Bae Kyung-hoon announced during the National Assembly audit that the AI model applied to the government business AI platform will be replaced with the second model of the independent foundation model (Dokpamo). This is a measure taken in response to criticism that the government-wide AI platform included Chinese AI models.

The passwords of over 75,000 Google Workspace accounts used by schools and educational institutions in the Daejeon area were changed without permission, and the Daejeon Metropolitan Office of Education took measures to suspend use and change them again.

DigitalX announced that it has launched a new app equipped with a generative artificial intelligence chatbot, the first domestic virtual asset exchange. Users can obtain market information and place orders by asking questions in natural language, and there is also a function to switch between Lite and Pro modes and a reward event when missions are achieved.

It was confirmed that the attacker IP used in the recent hacking incident at a major financial company also attempted to access Kakao Bank, K Bank, and Toss Bank servers several times, but it was detected and blocked by the security system, so no actual damage occurred, the financial industry announced.