1 hr ago
CrowdStrike Links Suspected China-Based Hacker to South Korean Bank Attacks
CrowdStrike says a person may have used AI tools during attacks on banks in South Korea.
The person may be 26 and live in Guangdong, China, but this has not been proven.
CrowdStrike said the tools included ARTEX and Claude Code.
ARTEX is designed to help test computer networks for weaknesses.
Its creators say it should not be used to attack real websites or online systems.
CrowdStrike said it found prompts about selling stolen Korean data and looking for related Telegram groups.
At least nine South Korean banks have been targeted since late September.
Two banks reported that customer information was exposed.
Police are investigating, and CrowdStrike’s identification of the suspect remains an assessment rather than a confirmed attribution.
CrowdStrike said a suspected attacker may be a 26-year-old based in Guangdong, China, but it has not attributed the activity to a named adversary.
The company said the suspect used ARTEX, an open-source penetration-testing AI agent, alongside large language models including Anthropic’s Claude Code.
CrowdStrike assessed with moderate confidence that the threat actor was likely Chinese-speaking and financially motivated, citing Chinese-language prompts and ARTEX use.
At least nine South Korean banks have disclosed or been reported as targets since late September; South Korean police launched a probe this week.
Shinhan Bank reported about 25,000 customers’ personal information compromised, while KB Kookmin Bank said information belonging to 119 customers was leaked.
- Who
- CrowdStrike reported that a suspected attacker may be a 26-year-old based in Guangdong, China; the activity has not been attributed to a named adversary.
- What
- Cyberattacks targeted South Korean financial institutions, and CrowdStrike said AI tools were used in activity associated with the campaign.
- Where
- South Korean financial institutions were targeted; the suspected attacker was said to be based in Guangdong, China.
- When
- The reported campaign ran from late September to early October; CrowdStrike published its report on Wednesday.
- Why
- CrowdStrike assessed with moderate confidence that the activity was financially motivated.
CrowdStrike’s assessment
Limits and stated tool purpose
Suspect’s identity and motive
CrowdStrike’s assessment
CrowdStrike said the suspected attacker may be a 26-year-old in Guangdong and assessed with moderate confidence that the actor was likely Chinese-speaking and financially motivated.
Limits and stated tool purpose
CrowdStrike said the activity has not been attributed to a named adversary. A man who answered a phone number in the report denied knowledge of the matter.
ARTEX’s use
CrowdStrike’s assessment
CrowdStrike said ARTEX was used alongside large language models in activity associated with attacks on South Korean financial institutions.
Limits and stated tool purpose
ARTEX’s GitHub page describes it as a tool for learning, code research, and local technical verification, and says it should not be used against real online systems or websites.
Key facts
- Suspected attacker
- Possibly a 26-year-old based in Guangdong, China; not confirmed
- Tools cited
- ARTEX and Anthropic’s Claude Code
- Campaign period
- Late September to early October
- Banks targeted
- At least nine South Korean banks disclosed or were reported as targets
- Shinhan Bank
- Reported personal information of about 25,000 customers compromised
- KB Kookmin Bank
- Reported personal information of 119 customers leaked
- Investigation
- South Korean police launched a probe this week
Quotes
CrowdStrike
US cybersecurity firm investigating the South Korean bank attacks.
“This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”
theprint.in
firstpost.com
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated.”
theprint.in
firstpost.com






