Business · Singapore Bureau
South Korean bank hack suspect identified as 26-year-old in China
Cybersecurity firm CrowdStrike has identified a potential suspect behind recent South Korean banking breaches as a 26-year-old individual based in China. The attacker allegedly used ARTEX, a newly released Chinese open-source penetration testing tool, to carry out the intrusions.
LSN Singapore ·

CrowdStrike's investigation into the South Korean banking cyber attacks has zeroed in on a specific suspect believed to be operating from within China. The identified individual is approximately 26 years old and is suspected of orchestrating intrusions targeting multiple South Korean financial institutions.
According to CrowdStrike's findings, the attacker employed ARTEX, an open-source penetration testing tool developed in China that has only recently been released. The use of this specialized tool provided investigators with a significant lead in attributing the attacks to a specific threat actor.
The discovery marks a notable development in ongoing cybersecurity investigations into breaches affecting South Korean banks. Penetration testing tools, while legitimate security instruments when used properly, can be weaponised by threat actors to identify vulnerabilities and gain unauthorised access to banking systems and sensitive financial data.
The findings have been shared with relevant South Korean authorities as investigations continue. The incident underscores persistent cyber threats facing financial institutions in the region and the evolving sophistication of attacks leveraging openly available hacking tools.