AI News Feed
Market watch
Cybersecurity

CrowdStrike Links Chinese-Speaking Hacker to AI-Driven Attacks on South Korean Banks

CrowdStrike says a Chinese-speaking hacker used AI tools and LLMs to breach South Korean banks, Yonhap reports.

In a report released Wednesday, U.S. time, CrowdStrike said the attacker used ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models to carry out the cyberattacks between late September and early October. The findings came as South Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank, reported a series of data breaches, prompting financial authorities and investigators to launch probes, according to Yonhap.

CrowdStrike said the compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees. The firm said the activity had not been attributed to a named adversary, but it assessed that the threat actor was likely a Chinese speaker and financially motivated.

"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in the report. The firm said its assessment was made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.

According to CrowdStrike, the attacker primarily used DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6 through Claude Code sessions. In one Claude Code session, the attacker asked Claude to draft a security researcher resume using personal details, including an age of 26 and an educational background at South China University of Technology in Guangdong, China.

CrowdStrike said the attacker's identity, the full extent of the breaches and the amount of stolen data remained unconfirmed. The firm also identified two servers used in the attacks: one based in Hong Kong serving as the attacker's primary infrastructure and another hosting ARTEX, which was likely used to target South Korean financial institutions.

An analysis of files showed the attacker asked Claude about marketplaces for stolen South Korean data and Telegram groups involved in selling such information, suggesting a possible financial motive, according to CrowdStrike.

Editor's Summary

CrowdStrike says a Chinese-speaking, financially motivated attacker used the Chinese-developed AI tool ARTEX and several large language models to breach South Korean banks. South Korean authorities are investigating data breaches at Hana Bank, KB Kookmin Bank and Shinhan Bank. CrowdStrike has not confirmed the attacker's identity or how much data was stolen.