ARTEX AI, Claude agents used in cyberattacks on South Korean banks
发布时间:2026-10-11 | 浏览:2
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
October 10, 2026
A Chinese-speaking hacker launched cyberattacks that shook the South Korean financial sector earlier this month, using the ARTEX AI penetration testing suite and Claude agents.
The actor targeted multiple Korean banks , including Shinhan Bank, KB Kookmin Bank, and Hana Bank, exposing clients ' personal data and credit card information, and causing system outages in some cases.
The South Korean government reacted with an emergency meeting and calls for immediate security measures for critical IT systems.
Security firm CrowdStrike confirmed the use of ARTEX AI, up until recently an open-source agentic penetration testing suite developed in China.
Researchers identified the attacker's infrastructure and found open directories with Claude Code session histories, ARTEX configuration files, and Claude memory files.
“The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions,” CrowdStrike explained.
“The threat actor likely accessed DeepSeek via the likely LLM API proxy/reseller xcai[.]pro,” the researchers noted .
These records also provided insight into the attacker’s activities, with targets overlapping those named in previous reporting about financial-sector breaches, allowing for high-confidence linking.
Because the threat actor used the same AI tools to create a résumé, they also exposed identification, contact, and Telegram account details.
Based on information in the résumé, CrowdStrike says that the attacker may be a 26-year-old Chinese who studied at the South China University of Technology and lives in Maoming, Guangdong, China.
However, the researchers found that the attacker initially provided a date of birth in 2007. Although the personal details may belong to the individual behind the ARTEX-related activity, they are not reliable enough to confirm the threat actor’s identity.
The records show the attacker had no specific plan to monetize the data stolen from South Korean banks, and asked Claude to propose Telegram data-sales groups focused on Korea.
After confirming that ARTEX had been used in real-world attacks, the developer decided to make the project closed-source and discontinue further updates.
However, the project’s current code has been used to create English- and Korean-language derivatives , so it’s still available in its current form.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Related Articles:
Anthropic asks Claude users to share voice data for AI model training
Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic wants Claude to analyze your bank account and financial data
Artificial Intelligence
Previous Article
Not a member yet? Register Now
You may also like:
Microsoft: Outdated Windows devices will stop receiving security updates
Microsoft: Outdated Windows devices will stop receiving security updates
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
FBI disrupts Chinese hacking tools used to breach critical infrastructure
FBI disrupts Chinese hacking tools used to breach critical infrastructure
Is your backup really out of reach? See what the latest attacks reveal.
Is your backup really out of reach? See what the latest attacks reveal.
AWS saw a valid key and let the agent clear a production bucket. See how Token Security ties each agent to its owner and limits it to read-only access.
AWS saw a valid key and let the agent clear a production bucket. See how Token Security ties each agent to its owner and limits it to read-only access.
Move from visibility to action with AITEM, Criminal IP’s next evolution of ASM
Move from visibility to action with AITEM, Criminal IP’s next evolution of ASM
Free Identity Governance for up to 150 Users: Try Our Community Edition
Free Identity Governance for up to 150 Users: Try Our Community Edition
New OAuth risk analyst agent: Turn 45 minutes of manual review into 15 seconds.
New OAuth risk analyst agent: Turn 45 minutes of manual review into 15 seconds.
Learn how to evaluate RMM security with eight practical tests. Find gaps before scaling endpoint management across customer environments.
Learn how to evaluate RMM security with eight practical tests. Find gaps before scaling endpoint management across customer environments.