1 hr ago

CrowdStrike Links Suspected China-Based Hacker to South Korean Bank Attacks

CrowdStrike Links Suspected China-Based Hacker to South Korean Bank Attacks
CrowdStrike says China-based suspect used AI tools in South Korean bank hacks · firstpost.com

CrowdStrike says a person may have used AI tools during attacks on banks in South Korea.

The person may be 26 and live in Guangdong, China, but this has not been proven.

CrowdStrike said the tools included ARTEX and Claude Code.

ARTEX is designed to help test computer networks for weaknesses.

Its creators say it should not be used to attack real websites or online systems.

CrowdStrike said it found prompts about selling stolen Korean data and looking for related Telegram groups.

At least nine South Korean banks have been targeted since late September.

Two banks reported that customer information was exposed.

Police are investigating, and CrowdStrike’s identification of the suspect remains an assessment rather than a confirmed attribution.

Key facts

Suspected attacker
Possibly a 26-year-old based in Guangdong, China; not confirmed
Tools cited
ARTEX and Anthropic’s Claude Code
Campaign period
Late September to early October
Banks targeted
At least nine South Korean banks disclosed or were reported as targets
Shinhan Bank
Reported personal information of about 25,000 customers compromised
KB Kookmin Bank
Reported personal information of 119 customers leaked
Investigation
South Korean police launched a probe this week

Quotes

CrowdStrike

US cybersecurity firm investigating the South Korean bank attacks.

“This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”
theprint.in firstpost.com
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated.”
theprint.in firstpost.com

Sources

Related news