Summary
- A suspected cyberattacker based in China may have used artificial intelligence tools to target South Korean financial institutions, according to cybersecurity company CrowdStrike.
- CrowdStrike said it identified personal information during its analysis of sessions involving AI coding tools and digital infrastructure connected to a hacking campaign that began in late September.
- According to the cybersecurity firm, the suspect used an AI session to ask about platforms where stolen Korean data could be sold and sought information about Telegram groups involved in the sale of compromised data.
A suspected cyberattacker based in China may have used artificial intelligence tools to target South Korean financial institutions, according to cybersecurity company CrowdStrike.
The company said the suspected attacker could be a 26-year-old individual from Guangdong province in southern China. CrowdStrike said it identified personal information during its analysis of sessions involving AI coding tools and digital infrastructure connected to a hacking campaign that began in late September.
At least nine South Korean banks have reportedly been targeted since late September, prompting an investigation by South Korean authorities.
CrowdStrike said the individual used ARTEX, a Chinese-developed open-source AI-powered penetration-testing tool, alongside Anthropic’s Claude Code. The company said the activity appeared to be financially motivated and assessed with moderate confidence that the suspect was a Chinese speaker.
According to the cybersecurity firm, the suspect used an AI session to ask about platforms where stolen Korean data could be sold and sought information about Telegram groups involved in the sale of compromised data.
In another interaction, the person reportedly asked an AI system to prepare a résumé for a security researcher. The document allegedly contained personal details including a Telegram account, age, educational information and a location in Maoming, Guangdong.
CrowdStrike cautioned that the activity has not been attributed to any specific named cyber adversary.
ARTEX is an open-source tool designed to automate aspects of penetration testing. It can connect with large language models such as Claude, ChatGPT and DeepSeek to assist organisations in identifying network vulnerabilities.
Its developers say the tool is intended for learning, coding research and local security testing and warn against using it to conduct unauthorised tests against live websites or online systems.
The reported attacks have raised fresh concerns about how cybercriminals could use AI agents to automate and accelerate attacks.
South Korean authorities have launched an investigation following the incidents, while President Lee Jae Myung has called for stronger measures to protect the country’s financial infrastructure.
Shinhan Bank previously reported that personal information belonging to about 25,000 customers had been compromised. KB Kookmin Bank also reported a data leak affecting 119 customers.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com

