Loading...
Chinese hacker used AI in South Korean bank attacks: CrowdStrike
The suspect is a 26-year-old from China

Chinese hacker used AI in South Korean bank attacks: CrowdStrike

Oct 08, 2026
01:27 pm

What's the story

A recent report by cybersecurity firm CrowdStrike has revealed that a 26-year-old suspect from China's Guangdong province may be behind the cyberattacks on South Korea's financial sector. The individual allegedly used a Chinese-developed AI tool called ARTEX and Anthropic's Claude Code in these attacks. The findings were made while analyzing AI coding-tool sessions and infrastructure related to a campaign against South Korean banks between late September and early October.

Tool details

ARTEX, Claude used in attacks

ARTEX, an open-source penetration testing tool developed in China, was used by the suspect along with large language models like Claude.

"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said.

This assessment was made with moderate confidence based on the use of ARTEX and observed Chinese-language prompts.

Investigation details

Suspect asked Claude where to sell stolen data

The suspect also asked Claude where hackers usually sell Korean data breach information and how to find Korean Telegram data sales groups.

In another session, they asked Claude to create a security researcher resume with details like a Telegram account, age, education background, and location in Maoming city of southern China's Guangdong province.

This was likely the attacker's actual location.

ADVERTISEMENT

Tool usage

What is ARTEX?

ARTEX, an open-source AI agent for automated penetration testing, was uploaded on GitHub this year by a Chinese security engineer known as Autumn.

It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude, and DeepSeek to help organizations test their networks for vulnerabilities.

The tool's GitHub page clearly states that it is meant for personal learning, code research, and local technical verification, not real-world testing against online systems or websites.

ADVERTISEMENT

Bank breaches

Personal information of customers compromised

Since late September, at least nine South Korean banks have been targeted by cyberattacks.

The attacks have prompted an investigation by the South Korean police and a call for strong response measures from President Lee Jae Myung.

Last week, Shinhan Bank revealed that the personal information of about 25,000 customers was compromised in the attack while KB Kookmin Bank reported a similar breach affecting 119 of its customers.

ADVERTISEMENT