The Maivia Gazette

Verified AI news, every morning

Security

CrowdStrike says a likely lone, Chinese-speaking attacker used AI pentesting tools to breach several South Korean banks

The intruder relied on the open-source ARTEX tool, running mainly on DeepSeek v4.1-flash through Claude Code sessions. More than 25,000 records were reportedly stolen at Shinhan Bank alone.

A cold-lit bank vault corridor with safe-deposit drawers pulled open and blank cards spilling toward an open hatch.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Independent reports. Security stories run only with a named disclosure or independent reporting behind them.

CrowdStrike reports that a suspected Chinese-speaking attacker broke into several South Korean financial institutions between late September and early October. The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July that uses language models to run penetration tests automatically. According to Yonhap, published by The Korea Times, the attacker mainly used DeepSeek v4.1-flash, with GLM-5.3 and Grok 4.6 as supplements, through Claude Code sessions. The compromised systems included one bank's loan inquiry service for financial brokers and another bank's mobile work-support system for employees. The Decoder, citing the Korean newspaper Khan, reports that more than 25,000 records were stolen at Shinhan Bank alone, including names, contact details, income and credit limits. CrowdStrike says the attacker's main infrastructure was a server in Hong Kong. Claude Code logs found in the attacker's open directories show the attacker asking about marketplaces and Telegram groups for selling stolen Korean data. In one session, the attacker requested a security researcher resume listing an age of 26 and study at South China University of Technology. South Korea's financial regulator held an emergency meeting, and President Lee Jae Myung called for a thorough investigation. The attacker's identity, the full scope of the intrusions and the amount of stolen data are still unconfirmed. CrowdStrike says the case shows how AI tools can let a single person carry out large breaches in a short time.

Sources

  1. CrowdStrike.comUnknown Threat Actor Uses AI-Driven ARTEX to Target South Korean FinancePublished · fetched
  2. The Korea TimesChinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report - The Korea TimesPublished · fetched
  3. The DecoderAI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banksPublished · fetched

Also in this edition