Science & Tech · Cybersecurity · 2 days ago

Account linked to Chinese DDoS group in probe of attacks on South Korean finance

Account linked to Chinese DDoS group in probe of attacks on South Korean finance

South Korean financial institutions were targeted in cyberattacks from late September to early October.

US security firm CrowdStrike said the attackers used the ARTEX penetration-testing tool and AI models including DeepSeek.

CrowdStrike linked the attacks to an account called YY520CN, whose user was reported to have said their phone number had been stolen and denied involvement.

South Korean security firm Logpresso later found signs that the account had served as a community supervisor in GodNet and VITAS, groups described as Chinese DDoS attack services.

Logpresso based its findings on comparisons of Telegram and GitHub records and credentials exposed by malware.

The account’s connection to those groups does not establish that its user carried out or led the attacks on financial institutions.

Logpresso says further checks could help verify the identities involved, and it urged organisations to review systems that can be accessed from outside and monitor unusual data lookups.

Sources

Related news