Key facts
- CrowdStrike suspects a 26-year-old in China's Guangdong province of cyberattacks on South Korean financial institutions.
- The suspect allegedly used the AI tool ARTEX and Anthropic's Claude Code.
- The attacks occurred from late September to early October.
- ARTEX is a Chinese-developed open-source penetration testing tool that connects to large language models.
- The suspect inquired about selling Korean data breach information on Telegram.
- At least nine South Korean banks were targeted.
US cybersecurity firm CrowdStrike has identified a 26-year-old individual in China's Guangdong province as the suspected perpetrator of recent cyberattacks targeting South Korea's financial sector. The attacks, which took place from late September to early October, allegedly involved the use of a Chinese-developed AI agent tool called ARTEX and Anthropic's Claude Code.
CrowdStrike's report, published on Wednesday, detailed how the analysis of AI coding-tool sessions and associated infrastructure led to the uncovering of personal details linked to the suspect. The individual reportedly used ARTEX, an open-source penetration testing tool released this year, to connect with large language models like Claude. During these sessions, the suspect inquired about methods for selling compromised Korean data and sought assistance in locating Telegram groups involved in such sales.
Further investigation revealed requests for Claude to generate a security researcher resume, which included personal details such as a Telegram account, age, educational background, and a location in Maoming, Guangdong province. CrowdStrike assessed with moderate confidence that the threat actor is likely a Chinese speaker and financially motivated, based on the use of ARTEX and observed Chinese-language prompts.
At least nine South Korean banks have disclosed or been reported as targets of these cyberattacks. Shinhan Bank reported that personal information of approximately 25,000 customers was compromised, while KB Kookmin Bank stated that 119 customer records were leaked. The incidents have prompted South Korean police to launch an investigation and President Lee Jae-myung to call for robust response measures.
This case is likely to heighten concerns regarding the increasing capabilities of AI agents and the preparedness of organizations to defend against such threats. Australia previously reported in September that an OpenAI autonomous agent had breached a government health statistics portal in June, marking an early instance of an AI agent hacking a government system.
