U.S. Cybersecurity Firm Reports AI-Powered Attacks on South Korean Banks by Suspected Chinese Hacker
U.S. cybersecurity firm CrowdStrike has reported that an unidentified hacker, believed to be a Chinese speaker, utilized artificial intelligence (AI)-powered hacking tools to breach multiple South Korean financial institutions and steal data. The attacks, which occurred between late September and early October, involved the use of ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models (LLMs) such as DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 through Claude Code sessions. Compromised systems included a bank's loan inquiry service for financial brokers and a mobile work-support system for employees. The attacker's use of Chinese-language prompts and a request to Claude to draft a security researcher resume with personal details, including an educational background at South China University of Technology, supports the assessment of a Chinese-speaking, financially motivated threat actor.