;

CrowdStrike, a U.S.-based cybersecurity company, disclosed its investigation into attacks on South Korean financial institutions from late September to early October. The attackers, believed to be Chinese-speaking, used AI-driven hacking tools combined with large language models to penetrate systems and steal data, likely motivated by financial gain. The perpetrators' identities and the extent of stolen data remain unconfirmed.
CrowdStrike, a U.S. cybersecurity service provider, revealed in a report that unidentified hackers, believed to be Chinese-speaking, used AI-powered hacking tools to attack multiple South Korean financial institutions and steal data from their systems.
CrowdStrike stated the attacks occurred from late September to early October, during which the perpetrators used ARTEX, an open-source penetration testing tool developed in China, along with large language models (LLMs) to carry out cyberattacks.
These incidents happened amid a period when many South Korean financial institutions, including Hana Bank, KB Kookmin Bank, and Shinhan Bank, faced data leaks and cyberattacks, prompting regulators and investigators in South Korea to intensify their inquiries.
CrowdStrike noted that the compromised systems included a credit data verification service used by financial brokers at one bank and a mobile support system for employees at another bank.
The company moderately confidently assessed the attackers as Chinese-speaking with financial motives, based on their use of ARTEX—a tool developed in China—and Chinese commands detected during the attack. However, CrowdStrike has not linked the attack to any specific hacker group or individual.
Analysis by CrowdStrike revealed the attackers primarily used DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6, working in conjunction with Anthropic's Claude Code.
In one Claude Code session, the attackers requested assistance in drafting a résumé for a cybersecurity research position, including personal details such as age 26, education at South China University of Technology in Guangdong Province, and information related to a Telegram account.
CrowdStrike indicated this data might belong to the attacker, also finding information linked to Maoming city in Guangdong Province, southern China. However, a man answering the phone number listed in CrowdStrike's report denied any knowledge of the matter.
Additionally, CrowdStrike detected two servers used in the attack: one located in Hong Kong serving as the attackers' main infrastructure, and another hosting ARTEX, likely utilized in the cyberattacks on South Korean financial institutions.
File analysis showed the attackers queried Claude about the market for trading stolen South Korean personal data from breaches and sought help locating Telegram groups involved in such data sales, leading CrowdStrike to conclude the attacks were financially motivated.
ARTEX is an open-source AI tool for automated penetration testing, released on GitHub this year by a Chinese cybersecurity engineer known as Autumn. It is not a standalone large language model but can connect with external LLMs like ChatGPT, Claude, and DeepSeek to assist organizations in identifying network vulnerabilities.
ARTEX's GitHub page states the tool is intended for personal learning, code research, and technical audits on local systems and should not be used to test live online systems or websites without authorization.
This situation raises concerns about the use of AI agents—AI systems capable of autonomous multi-step operations—in cyberattacks and questions organizations' readiness to defend against such emerging threats.
Previously, in September, Australia disclosed that OpenAI's autonomous AI agents had breached a government health statistics website in June, regarded as one of the first public cases of AI agents being used in government system attacks.
In South Korea, local media reported that at least nine financial institutions acknowledged being targets of cyberattacks since late September, prompting investigations by South Korean police and calls from President Lee Jae-myung for strong countermeasures and protection.
Shinhan Bank revealed last week that personal data of about 25,000 customers were accessed without authorization, while KB Kookmin Bank reported a leak involving personal data of 119 customers.
However, the true identity of the attackers, the full extent of the breach, and the volume of stolen data remain under investigation and have not been officially confirmed. Anthropic, South Korean police, and China's Ministry of Foreign Affairs have yet to comment on the report.