Ads_970x250

CrowdStrike Says AI Tools Used in South Korea Bank Hacks

The cybersecurity firm says a financially motivated attacker used agentic AI alongside conventional hacking, with clues pointing to a possible China-based operator.

Topics

  • A suspected attacker behind cyber intrusions targeting South Korean financial institutions used agentic AI tools alongside conventional hacking techniques, according to CrowdStrike.

    The cybersecurity firm said it traced infrastructure used in attacks from late September to early October and found ARTEX configuration files, Claude Code session histories and Claude memory files that revealed how the attacker operated. CrowdStrike.com

    ARTEX is an open-source agentic penetration-testing tool developed in China that can connect to large language models and automate parts of vulnerability testing. 

    CrowdStrike said the instance it examined mainly used DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 used in other sessions. CrowdStrike.com

    CrowdStrike has not attributed the campaign to a known hacking group or the Chinese government.

    “While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” the company said.

    It made the assessment with “moderate confidence” based partly on Chinese-language prompts and the tools used.

    The investigation also found that the attacker asked Claude for information about where stolen Korean data is typically sold and sought help locating Korean Telegram groups used for data sales.

    In another session, the user asked Claude to create a security researcher résumé containing an age of 26, an education history and a location in Maoming, Guangdong.

    CrowdStrike said the details likely belonged to the person conducting the activity, but could not establish that definitively.

    The findings come as South Korean authorities investigate attacks on at least nine banks.

    Shinhan Bank said data belonging to about 25,000 customers was compromised, while KB Kookmin Bank disclosed a breach affecting 119 customers. 

    South Korean President Lee Jae Myung said this week that AI appeared to have been used in the attacks and ordered authorities to investigate quickly and strengthen their response. 

    CrowdStrike said the case shows how agentic AI can help a financially motivated attacker carry out multiple intrusions more quickly, while still relying on conventional hacking techniques. It expects attackers to keep experimenting with AI to increase the speed and scale of cyber operations.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.