Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

CrowdStrike Says South Korean Bank Hack Suspect May Be a 26-Year-Old Using ARTEX and Claude Code

Дата публикации: 08-10-2026 07:33:21

The suspect behind recent cyberattacks on South Korea’s financial sector may be a 26-year-old in China’s Guangdong province. In a report published Wednesday, U.S. cybersecurity firm CrowdStrike said it found personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure tied to a campaign running from late September to early October. […]

Основное содержимое страницы с новостью.

AI Coding - Clues - Suspect - South Korean-Bank-Breaches

Key Takeaways

  • Suspect Identified: CrowdStrike says the attacker may be a 26-year-old based in China’s Guangdong province.

  • AI Tools Used: The suspect allegedly used ARTEX, a Chinese-developed AI agent, and Anthropic’s Claude Code.

  • Nine Banks Targeted: At least nine South Korean banks have disclosed, or been reported as, targets since late September.

The suspect behind recent cyberattacks on South Korea’s financial sector may be a 26-year-old in China’s Guangdong province. In a report published Wednesday, U.S. cybersecurity firm CrowdStrike said it found personal details linked to the suspected attacker while analyzing AI coding-tool sessions and infrastructure tied to a campaign running from late September to early October.

Claude Sessions Point to Maoming, Guangdong

CrowdStrike said the individual asked Claude where threat actors typically sell Korean data breach information and sought help finding Korean Telegram data sale groups. 

In another session, the person asked Claude to create a security researcher resume. It listed a Telegram account, age, educational background, and a location in Maoming, a city in southern Guangdong, which CrowdStrike said likely belonged to the attacker.

A man who answered a phone number provided in the report said he knew nothing about the matter, and Anthropic, South Korean police, and China’s foreign ministry did not immediately respond to requests for comment, according to Reuters.

What Is ARTEX? The Chinese AI Penetration Testing Tool

ARTEX is an open-source AI agent for automated penetration testing, published on GitHub this year by a Chinese security engineer using the handle “Autumn.” It is not a standalone large language model (LLM), but connects to external models such as ChatGPT, Claude, and DeepSeek to help organizations test their networks for vulnerabilities. 

Its GitHub page says it is meant for personal learning, code research and local technical verification, not real-world testing against online systems or websites.

CrowdStrike has not attributed the activity to a named adversary. It said, with moderate confidence, that the actor is likely a Chinese speaker and financially motivated, based on ARTEX use and Chinese-language prompts.

“Activity at multiple organizations purportedly involved overlapping IP addresses,” CrowdStrike said. “Reporting also suggested the attacker used ARTEX based on references to the string ARTEX in HTML files observed on a reportedly threat actor-controlled server.”

Shinhan Bank and KB Kookmin Bank Customer Data Compromised

Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, and Hyundai Capital suffered data breaches between September 27 and 30, reports say. 

Shinhan Bank said last week that personal information of 25,727 customers was compromised. KB Kookmin Bank said 119 customers’ personal information was leaked, and Hana Bank said 89. 

AI Agent Attacks Raise Security Concerns

The case is likely to intensify concerns over AI agents and whether organizations can defend against them. 

Australia said last month that an OpenAI autonomous agent breached a government health statistics portal in June, one of the first known cases of an AI agent hacking a government system.

In other recent news, suspected AI-linked cyberattacks targeting two Seoul megachurches may have exposed data of 850,000 members. In August, feds warned that hackers now use AI to write exploits targeting U.S. water systems’ Siemens PLCs.

Explore More

Most Popular

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Suspect behind South Korea bank hacks may be 26-year-old in China, CrowdStrike says 06.1408-10-2026
2AI Tools and Sloppy Opsec Expose Suspected Chinese Hacker Behind South Korean Bank Breaches08.3309-10-2026
3Chinese AI Agent Pulled From Public View After Breaching South Korean Banks011.6409-10-2026
4Chinese developer makes ARTEX AI agent closed-source after Korean bank hack 09.0709-10-2026
5South Korea’s Banks Under AI-Assisted Assault: President Lee Demands Answers015.8508-10-2026
6Un agent IA offensif industrialise les compromissions : autopsie des attaques ARTEX08.6508-10-2026
7South Korea warns of possible AI use in banking hacks07.5406-10-2026
8China-linked hackers backdoored executives' laptops via USB, exploiting a fix companies had but weren't using010.403-09-2026
9В Южной Корее выявили утечки в десятках организаций в результате кибератак08.3306-10-2026
10China-linked hackers posed as former US officials, Anthropic employee to target AI experts010.3701-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.73. Источник: www.technadu.com.