Science & Tech · Cybersecurity · 2 days ago
Account linked to Chinese DDoS group in probe of attacks on South Korean finance
South Korean financial institutions were targeted in cyberattacks from late September to early October.
US security firm CrowdStrike said the attackers used the ARTEX penetration-testing tool and AI models including DeepSeek.
CrowdStrike linked the attacks to an account called YY520CN, whose user was reported to have said their phone number had been stolen and denied involvement.
South Korean security firm Logpresso later found signs that the account had served as a community supervisor in GodNet and VITAS, groups described as Chinese DDoS attack services.
Logpresso based its findings on comparisons of Telegram and GitHub records and credentials exposed by malware.
The account’s connection to those groups does not establish that its user carried out or led the attacks on financial institutions.
Logpresso says further checks could help verify the identities involved, and it urged organisations to review systems that can be accessed from outside and monitor unusual data lookups.
South Korean security company LogPresso reported that an account identified by US cybersecurity firm CrowdStrike as a suspect in attacks on South Korean financial institutions had links to the Chinese DDoS-for-hire groups GodNet and VITAS.
LogPresso said the account, YY520CN, appeared to have served as a community supervisor who managed members of the groups.
CrowdStrike had previously said the attacks used the Chinese AI penetration-testing tool ARTEX and AI models including DeepSeek.
The suspect was reported to have denied involvement, saying their mobile phone number had been used without permission.
LogPresso said further checks would be needed to verify the suspect’s identity and whether they directed the attacks.
- Who
- The YY520CN account user, identified by CrowdStrike as a suspect; LogPresso investigated the account’s links to GodNet and VITAS.
- What
- An investigation found signs that the account was active in Chinese DDoS-for-hire groups while the user denied involvement in attacks on South Korean financial institutions.
- When
- The findings were reported on October 9, 2026; the attacks took place from late September to early October, according to the articles.
- Where
- South Korean financial institutions were targeted; the suspect was reported to possibly live in Guangdong, China.
- Why
- Not stated
YY520CN account user
LogPresso
Involvement in the financial-sector attacks
YY520CN account user
The user reportedly said their phone number had been used without permission and denied any connection to the hacking.
LogPresso
LogPresso found evidence that the YY520CN account had been active in GodNet and VITAS, but said whether the user led the attacks still required verification.
Identity and account links
YY520CN account user
The user’s denial challenges the link between the account and the attacks.
LogPresso
LogPresso said it could use account records, leaked credentials and other information to cross-check the identity, but described this as a further verification step.
No direct quotes in the coverage so far.
The HangHang2017 account was found to have left traces after a device was infected with an infostealer, according to LogPresso.
CrowdStrike analyzed attacks targeting South Korean financial institutions and said the attackers used ARTEX and AI models including DeepSeek.
LogPresso published its follow-up analysis reporting links between YY520CN and GodNet and VITAS.
- Suspect account
- YY520CN
- Groups identified by LogPresso
- GodNet and VITAS
- Role attributed to YY520CN
- Community supervisor who managed members
- Other account examined
- HangHang2017
- Reported possible location and age of suspect
- Guangdong, China; 26 years old











