A suspected Chinese-speaking hacker used AI-powered penetration testing tools to target South Korean financial institutions in a campaign that resulted in stolen data, according to new CrowdStrike research.
The activity occurred from late September through early October 2026, although the total number of affected organizations remains unconfirmed, at least five lenders affected include Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank
The attacker used ARTEX, an open-source agentic penetration testing tool developed in China, alongside several LLMs. CrowdStrike identified exposed attacker-controlled directories containing Claude Code session histories, ARTEX configuration files and AI memory files. The ARTEX deployment used DeepSeek v4.1-flash as its primary model, while additional sessions involved GLM-5.3 and Grok 4.6.
According to reports examined by CrowdStrike, one affected bank’s loan inquiry service used by financial brokers was breached, while another bank’s employee mobile work-support system was compromised.
The recovered AI conversations also showed the attacker asking Claude where stolen Korean data could be sold and seeking assistance locating Telegram groups involved in data sales.
ㅤRyan McCurdy, VP of Marketing, Liquibase:
“AI is changing the economics of cyberattacks. Tools that once required considerable expertise can now be combined with AI agents that help attackers find weaknesses, test approaches, and operate across multiple targets.
“ That has significant implications for companies running open-source software. Vulnerabilities aren’t new, but the time between discovering one and exploiting it could get much shorter as these capabilities improve.
“Enterprises need to reconsider how they manage that exposure. It’s no longer enough to know that a vulnerability exists or that a patch is available. You need to know where you’re exposed, who owns remediation, and how quickly you can safely deploy a fix.
“Open source isn’t inherently less secure. But as AI accelerates offensive capabilities, relying on community-driven remediation without clear ownership, support commitments, or a tested response process becomes a much harder risk to justify.”
ㅤOpen source anything isn’t going to keep costs down. At least not if you think that you don’t have to follow proper security standards.
Related
This entry was posted on October 8, 2026 at 6:34 pm and is filed under Commentary with tags China, South Korea. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Hacker uses AI-powered attack tools to breach South Korean banks
A suspected Chinese-speaking hacker used AI-powered penetration testing tools to target South Korean financial institutions in a campaign that resulted in stolen data, according to new CrowdStrike research.
The activity occurred from late September through early October 2026, although the total number of affected organizations remains unconfirmed, at least five lenders affected include Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank
The attacker used ARTEX, an open-source agentic penetration testing tool developed in China, alongside several LLMs. CrowdStrike identified exposed attacker-controlled directories containing Claude Code session histories, ARTEX configuration files and AI memory files. The ARTEX deployment used DeepSeek v4.1-flash as its primary model, while additional sessions involved GLM-5.3 and Grok 4.6.
According to reports examined by CrowdStrike, one affected bank’s loan inquiry service used by financial brokers was breached, while another bank’s employee mobile work-support system was compromised.
The recovered AI conversations also showed the attacker asking Claude where stolen Korean data could be sold and seeking assistance locating Telegram groups involved in data sales.
ㅤRyan McCurdy, VP of Marketing, Liquibase:
“AI is changing the economics of cyberattacks. Tools that once required considerable expertise can now be combined with AI agents that help attackers find weaknesses, test approaches, and operate across multiple targets.
“ That has significant implications for companies running open-source software. Vulnerabilities aren’t new, but the time between discovering one and exploiting it could get much shorter as these capabilities improve.
“Enterprises need to reconsider how they manage that exposure. It’s no longer enough to know that a vulnerability exists or that a patch is available. You need to know where you’re exposed, who owns remediation, and how quickly you can safely deploy a fix.
“Open source isn’t inherently less secure. But as AI accelerates offensive capabilities, relying on community-driven remediation without clear ownership, support commitments, or a tested response process becomes a much harder risk to justify.”
ㅤOpen source anything isn’t going to keep costs down. At least not if you think that you don’t have to follow proper security standards.
Share this:
Like this:
Related
This entry was posted on October 8, 2026 at 6:34 pm and is filed under Commentary with tags China, South Korea. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.