CrowdStrike Says AI Tools Used in South Korea Bank Hacks
The cybersecurity firm says a financially motivated attacker used agentic AI alongside conventional hacking, with clues pointing to a possible China-based operator.
Topics
News
- Fired OpenAI Researchers Warn Dismissals Could Chill Safety Work
- ARTEX Developer Closes AI Hacking Tool After Bank Attacks
- AI Redraws Global Race for Quant Talent as Coding Tools Lower Entry Barriers
- AI Dispatch | India Draws Billions Into AI
- AI Bots Now Make Up Half of Traffic to US Fed’s FRED Database
- Musk Blames ‘Oligarchs’ For Delay in Starlink’s India launch
A suspected attacker behind cyber intrusions targeting South Korean financial institutions used agentic AI tools alongside conventional hacking techniques, according to CrowdStrike.
The cybersecurity firm said it traced infrastructure used in attacks from late September to early October and found ARTEX configuration files, Claude Code session histories and Claude memory files that revealed how the attacker operated. CrowdStrike.com
ARTEX is an open-source agentic penetration-testing tool developed in China that can connect to large language models and automate parts of vulnerability testing.
CrowdStrike said the instance it examined mainly used DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 used in other sessions. CrowdStrike.com
CrowdStrike has not attributed the campaign to a known hacking group or the Chinese government.
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” the company said.
It made the assessment with “moderate confidence” based partly on Chinese-language prompts and the tools used.
The investigation also found that the attacker asked Claude for information about where stolen Korean data is typically sold and sought help locating Korean Telegram groups used for data sales.
In another session, the user asked Claude to create a security researcher résumé containing an age of 26, an education history and a location in Maoming, Guangdong.
CrowdStrike said the details likely belonged to the person conducting the activity, but could not establish that definitively.
The findings come as South Korean authorities investigate attacks on at least nine banks.
Shinhan Bank said data belonging to about 25,000 customers was compromised, while KB Kookmin Bank disclosed a breach affecting 119 customers.
South Korean President Lee Jae Myung said this week that AI appeared to have been used in the attacks and ordered authorities to investigate quickly and strengthen their response.
CrowdStrike said the case shows how agentic AI can help a financially motivated attacker carry out multiple intrusions more quickly, while still relying on conventional hacking techniques. It expects attackers to keep experimenting with AI to increase the speed and scale of cyber operations.


