Hacker who hit Korean banks likely from China, CrowdStrike says


Cybersecurity experts flagged that an AI tool named ARTEX, developed in China for defensive purposes, was involved in the cyberattacks. — Image by Magnific

The hacker suspected of infiltrating some of South Korea’s largest banks this month may have used artificial intelligence (AI) tools to carry out the attacks from China, cybersecurity firm CrowdStrike says, shedding new light on an incident that’s shaken the nation’s financial sector.

The person used Anthropic’s Claude to conduct research and create a resume that likely belonged to the perpetrator of the cyber-intrusion, the US firm said. The profile identified the alleged attacker as a 26-year-old based in Guangdong, it said. 

The report outlined the US firm’s findings in the wake of data breaches at multiple South Korean financial institutions last week. South Korean police are investigating the hacks, which are believed to have impacted some 68,000 people, including about 40,000 customers at Yegaram Savings Bank and 25,000 at Shinhan Bank.

"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts,” CrowdStrike wrote in its report. "While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated.”

Cybersecurity experts flagged that an AI tool named ARTEX, developed in China for defensive purposes, was involved in the cyberattacks. 

The open nature of AI models may be helping investigators gather clues. CrowdStrike stressed that it couldn’t definitively establish the identity of the attacker, but based its assessments on the person’s Claude Code session histories and other digital clues they left behind. 

CrowdStrike said the suspected attacker likely used a Hong Kong-based IP address to target the Korean lenders. The person may have used DeepSeek’s V4.1 Flash – a model unveiled last month – along with tools released by Z.ai and Elon Musk’s x.AI. IP addresses linked to the hacks had hosted open directories containing Claude activity, CrowdStrike wrote. 

The person also asked Claude to help find Korean data sales groups on the messaging app Telegram, the US firm said. Claude is banned in China but can be accessed via virtual private networks. 

On Oct 4, South Korea’s Financial Services Commission said it hadn’t found any evidence that financial account data was leaked to China. – Bloomberg

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

Others Also Read