AI-Driven Cyberattacks Target South Korean Banks

Sanaa:CrowdStrike An unidentified hacker, believed to be a Chinese speaker, used AI-powered tools to breach several South Korean financial institutions, stealing valuable data.

According to Yonhap News Agency, the U.S. cybersecurity firm CrowdStrike reported that the attacker utilized ARTEX, an open-source AI-powered penetration-testing tool developed in China, along with large language models (LLMs) to conduct cyberattacks between late September and early October.

This breach has affected major South Korean banks, including Hana Bank, KB Kookmin Bank, and Shinhan Bank, prompting financial authorities and investigators to initiate investigations. The compromised systems included a loan inquiry service used by financial brokers and a mobile work-support system for bank employees.

CrowdStrike has not attributed the activities to a specific adversary, but the hacker is suspected to be a Chinese speaker with financial motives. This assessment is based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.

The attacker primarily employed DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6 through sessions with Claude Code. In one instance, the attacker asked Claude to draft a security researcher resume using personal details from the South China University of Technology in Guangdong, China.

While the hacker's identity and the full extent of the breaches remain unknown, CrowdStrike identified two servers used in the attacks one based in Hong Kong as the main infrastructure and another hosting ARTEX, likely targeting South Korean banks. Analysis revealed the attacker inquired about marketplaces for stolen South Korean data and Telegram groups selling such information, suggesting a financial motive.