Chinese Hacker Deployed AI in Campaign Against South Korean Banks
A suspected Chinese attacker used ARTEX and Claude to breach South Korean banks and steal customer data.
CrowdStrike says a financially motivated, likely Chinese-speaking attacker used the open-source agentic tool ARTEX and Anthropic's Claude from late September to early October 2026 to find vulnerabilities and compromise South Korean financial firms. Attacker infrastructure used DeepSeek v4.1-flash as ARTEX's main model, plus GLM-5.3 and Grok 4.6, and Claude was asked to find Korean Telegram groups for selling stolen data. Shinhan Bank and Yegaram Savings Bank reported breaches affecting about 25,000 and 40,000 people. South Korea's Financial Services Commission warned customers on October 6 about phishing and loan scams.
- ARTEX and Claude were used to find and compromise services at Korean financial firms.
- Shinhan Bank and Yegaram Savings Bank reported 25,000 and 40,000 affected people.
- Backends included DeepSeek v4.1-flash, GLM-5.3, Grok 4.6, and Claude.
- CrowdStrike has moderate confidence the actor is a Chinese speaker seeking money.
- Korea's regulator warned customers about phishing and loan scams.
Full article495 words · extracted from infosecurity-magazine.com · click to collapse
A suspected China-based threat actor leveraged AI tooling in a campaign that successfully exfiltrated data from South Korean financial organizations, CrowdStrike has revealed.
The cybersecurity firm discovered that the attacker used ARTEX, a recently released open-source agentic pentesting tool developed in China alongside Anthropic’s Claude AI model during the campaign, which ran from late September to early October 2026.
The threat actor primarily used ARTEX to discover vulnerabilities and compromise specific services in victim organizations. They also asked Claude for assistance in finding Korean Telegram data sales groups to try and sell the stolen information.
“The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft. This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span,” CrowdStrike wrote in a blog published on October 7.
Following its investigation, CrowdStrike has assessed with moderate confidence that the attacker is a Chinese speaker and financially motivated.
AI Tools Tied to Attacker-Controlled Infrastructure
The researchers were able to link all the attacks to the same IP address, which allowed them to uncover the threat actor’s deployment of AI during the campaign.
The IP address hosted an ARTEX instance and open directory containing a Claude Code markdown document, which contained a Chinese-language pentesting prompt that specified how the large language model (LLM) should conduct pentesting activities.
The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (from Chinese firm Zhipu AI) and Grok 4.6 for additional Claude Code sessions.
Another threat actor-controlled Hong Kong–based IP address appeared in the document, which was assessed to serve the primary attacker-controlled infrastructure. This IP address was found to contain additional open directories that contained Claude Code session histories, ARTEX configuration files and Claude memory files.
In one Claude Code session, the user issued a prompt that contained personal details, including the Telegram username YY520CN and location of Maoming, Guangdong, China. CrowdStrike said it is likely these details belong to the threat actor who conducted the ARTEX-related activity.
Campaign Results in Large-Scale Data Breaches
The campaign reportedly resulted in data being exfiltrated from a number of South Korea-based financial firms. This included Shinhan Bank and Yegaram Savings Bank, who reported breaches affecting 25,000 and 40,000 people, according to Singapore-based newspaper The Straits Times.
At one affected bank, the threat actor reportedly breached a loan progress inquiry service used by financial brokers. At another bank, the attacker compromised an employee mobile work–support system.
CrowdStrike emphasized that the total number of organizations affected remains unconfirmed at the time of writing.
South Korea’s Financial Services Commission issued a consumer alert relating to the attacks on October 6. This warned customers of the hacked companies to be vigilant over potential phishing attacks and loan scams.
The agency added that affected organizations will continue to investigate the extent of the data breaches and provide updates accordingly.