Solo Hacker Used AI Tools to Breach South Korean Financial Organizations and Steal Data
Suspected lone Chinese-speaking hacker used ARTEX AI pentest tool to breach Shinhan, Kookmin, Hana and other South Korean financial firms, stealing customer data.
A suspected lone operator used ARTEX, an open-source China-developed agentic penetration-testing tool, to breach multiple South Korean financial organizations between late September and early October 2026. Victims include Shinhan Bank, Kookmin Bank, Hana Bank, BNK Busan Bank, Hyundai Capital, and several savings banks and online lenders, though core banking platforms were not compromised. CrowdStrike found exposed Claude Code session records and ARTEX configs on actor infrastructure, showing use of DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 as AI backends. CrowdStrike assessed with moderate confidence the actor was Chinese-speaking and financially motivated, and not linked to a known threat group.
- Lone actor used open-source ARTEX agentic AI tool against multiple Korean financial firms.
- CrowdStrike assesses Chinese-speaking, financially motivated actor; no known group link.
- Operator cycled DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 via Claude Code sessions.
- Core banking untouched; weaker broker portals and employee systems were targeted.
- Exposed ARTEX server leaked session records, configs, and likely workflow details.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | xcai.pro | de Code sessions. The actor likely reached DeepSeek through xcai[.]pro , described by CrowdStrike as a likely API proxy or resel |
Full article982 words · extracted from cybersecuritynews.com · click to collapse
A suspected lone threat actor used an AI-powered penetration-testing tool called ARTEX to breach several South Korean financial organizations and steal customer and employee data.
The activity, which ran from late September to early October 2026, affected banks, savings banks, capital firms, and online lending services. The case shows how open-source AI tools can help a single operator run fast, wide-scale intrusion activity against many targets.
The breaches reportedly exposed sensitive information from systems that were less protected than core banking platforms. At Shinhan Bank, the actor reportedly accessed a loan-progress inquiry service used by financial brokers.
At Kookmin Bank, the intruder compromised an internal mobile work-support system for employees. Reports said the wider incident also affected Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital, Welcome Savings Bank, and two online lending firms, although the full number of affected organizations remains unconfirmed.
Analysts at CrowdStrike identified infrastructure tied to the campaign and found exposed directories containing Claude Code session records, ARTEX configuration files, and Claude memory files.
These artifacts gave researchers an unusual view into the operator’s tools, AI model choices, infrastructure, and likely workflow.
CrowdStrike said the activity has not been linked to a known threat group, but assessed with moderate confidence that the actor was likely Chinese-speaking and financially motivated.
Solo Hacker Used AI Tools
ARTEX is an open-source, China-developed agentic penetration-testing tool. In normal and authorized use, tools of this type can help security teams test systems, find weak points, and validate fixes.
In this case, the operator appears to have used the same automation for harmful activity against South Korean finance organizations. According to local reporting, ARTEX was released on GitHub on July 26, 2026, only weeks before the breaches.
Investigators found the string “ARTEX-自主渗透試控制台,” translated as “autonomous penetration test console,” in HTML content on infrastructure linked to the activity.
The timing raised concern because the tool quickly moved from a public project to a suspected real-world breach campaign. The reported intrusions did not appear to compromise core internet or mobile banking systems.
Instead, the actor focused on connected services that may have had weaker controls. In one case, the intruder reportedly entered random values into a loan-broker service to identify valid customer numbers, then collected related records. This method may explain why systems holding smaller but still valuable sets of personal data became targets.
Two-Server Setup and Multiple AI Models
CrowdStrike’s review pointed to a two-server setup. A Hong Kong-based server appeared to be the main infrastructure used by the actor, while 38.244.50[.]120 hosted the ARTEX instance believed to be involved in the South Korean activity.
The exposed ARTEX server also contained a Chinese-language prompt that instructed a large language model on how to perform penetration-testing tasks.
The ARTEX instance used DeepSeek v4.1-flash as its main AI backend. CrowdStrike also found evidence that the operator used GLM-5.3 from Zhipu AI and Grok 4.6 in other Claude Code sessions.
The actor likely reached DeepSeek through xcai[.]pro, described by CrowdStrike as a likely API proxy or reseller. This mix of models suggests the operator used AI as a flexible working layer for research, command generation, and task support rather than relying on one service alone.
The exposed sessions also showed the actor asking Claude where stolen South Korean breach data is usually sold and requesting help locating Korean Telegram data-sale groups.
That detail supports CrowdStrike’s assessment that financial gain, rather than espionage, was likely the main motive. However, such requests alone do not prove that data was sold or that a specific person carried out the breaches.
This incident is important because it shows how AI can reduce the time and skill needed to coordinate many parts of an intrusion. The main risk is not that AI creates every exploit from nothing.
It can speed up target research, scan analysis, testing, scripting, record keeping, and the use of existing tools. That shorter cycle can allow a small team, or even one person, to probe more organizations before defenders identify and block the activity.
The pattern fits other recent reporting on AI-assisted cybercrime. Cyber Security News previously covered Claude AI agents used to automate cyberattacks, where AI helped actors speed up reconnaissance, malware work, and data theft.
It also reported on a Russian actor’s AI-powered penetration-testing platform and the Xalgorix AI penetration-testing tool, showing how agentic tools are becoming more accessible to both defenders and criminals.
For financial organizations, the lesson is clear: security reviews must include broker portals, employee systems, support services, APIs, and other connected applications—not just core banking platforms.
Organizations should enforce strong authentication, limit automated requests, monitor unusual lookups of customer records, separate sensitive systems, and quickly investigate traffic from known malicious infrastructure.
Indicators of compromise (IoCs):-
| Indicator | Type | Reported role |
|---|---|---|
38.244.50[.]120 | IP address | Threat actor-controlled server hosting the ARTEX instance |
101.53.80[.]20 | IP address | Proxy used during ARTEX-related activity |
205.214.59[.]31 | IP address | Proxy used during ARTEX-related activity |
124.155.252[.]63 | IP address | Proxy used during ARTEX-related activity |
154.201.79[.]246 | IP address | Proxy used during ARTEX-related activity |
23.248.249[.]90 | IP address | Proxy used during ARTEX-related activity |
23.158.220[.]98 | IP address | Proxy used during ARTEX-related activity |
103.248.148[.]84 | IP address | Proxy used during ARTEX-related activity |
203.160.133[.]172 | IP address | Proxy used during ARTEX-related activity |
209.209.85[.]38 | IP address | Proxy used during ARTEX-related activity |
xcai[.]pro | Domain | Likely DeepSeek API proxy or reseller used by the actor |
http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md | URL | Exposed Claude Code markdown document on the ARTEX server |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.