CrowdStrike says China-based suspect used AI tools in South Korean bank hacks

SEOUL: The suspect behind recent cyberattacks targeting South Korea’s financial sector may be a 26-year-old based in China’s Guangdong province who used a Chinese-developed AI agent tool called ARTEX and Anthropic’s


Business

CrowdStrike says China-based suspect used AI tools in South Korean bank hacks

CrowdStrike says China-based suspect used AI tools in South Korean bank hacks

The CrowdStrike logo is displayed on the Sphere in Las Vegas, Nevada, US on Sep 1, 2026. (Photo: Reuters/Raphael Satter)

Read a summary of this article on FAST.

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

SEOUL: The suspect behind recent cyberattacks targeting South Korea’s financial sector may be a 26-year-old based in China’s Guangdong province who used a Chinese-developed AI agent tool called ARTEX and Anthropic’s ClaudeCode, US cybersecurity firm CrowdStrike said.

In a report published on Wednesday (Oct 7), CrowdStrike said it uncovered personal details linked to the suspected attacker while analysing AI coding-tool sessions and infrastructure associated with a campaign targeting South Korean financial institutions from late September to early October.

The case is likely to intensify concerns over the rise of AI agents and whether organisations are prepared to defend their systems against them.

Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, marking one of the first known instances of an AI agent hacking a government system.

Guess Word

Guess Word
Crack the word, one row at a time


Buzzword

Buzzword
Create words using the given letters


Mini Sudoku

Mini Sudoku
Tiny puzzle, mighty brain teaser


Mini Crossword

Mini Crossword
Small grid, big challenge


Word Search

Word Search
Spot as many words as you can


Show More


Show Less

CrowdStrike said the attacker used ARTEX, a recently released Chinese-developed open-source penetration testing tool, alongside large language models such as Claude.

“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” it said.

“This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”


BANK HACKS

CrowdStrike said the individual also asked Claude where threat actors typically sell Korean data breach information and sought assistance in finding Korean Telegram data sales groups.

In another session, the person also asked Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number provided by CrowdStrike in its report said he had no knowledge of the matter.

Anthropic, South Korean police and China’s foreign ministry did not immediately respond to requests for comment.

ARTEX is an open-source AI agent for automated penetration testing that was published on GitHub this year by a Chinese security engineer with the handle Autumn. It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to help organisations test for vulnerabilities in networks.

The tool’s GitHub page says it is intended for personal learning, code research and local technical verification and should not be used to conduct real-world testing against online systems or websites.

At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures.

Shinhan Bank said last week that the personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

Source: Reuters/nh

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Inbox

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Whatsapp

Get bite-sized news via a new
cards interface. Give it a try.

Click here to return to FAST
Tap here to return to FAST

FAST

Leave a Reply

Your email address will not be published. Required fields are marked *

About the Author

Easy WordPress Websites Builder: Versatile Demos for Blogs, News, eCommerce and More – One-Click Import, No Coding! 1000+ Ready-made Templates for Stunning Newspaper, Magazine, Blog, and Publishing Websites.

BlockSpare — News, Magazine and Blog Addons for (Gutenberg) Block Editor

Search the Archives

Access over the years of investigative journalism and breaking reports