CrowdStrike links South Korean bank hacks to China-based attacker using AI

Sundry Photography
U.S. cybersecurity firm CrowdStrike (CRWD) said a suspected China-based attacker used AI tools to target South Korean financial institutions between late September and early October.
CrowdStrike (CRWD) said the unidentified threat actor used Chinese-developed ARTEX, an open-source AI penetration-testing tool, alongside large language models. The firm assessed with moderate confidence that the attacker was a Chinese speaker and financially motivated.
CrowdStrike (CRWD) also found Claude Code session records containing personal details that may point to a 26-year-old based in Guangdong, China. However, the firm said it could not definitively associate those details with the attacker.
At least nine South Korean banks have reported or been linked to cyberattacks since late September. Shinhan Bank said about 25,000 customers' personal information was compromised, while KB Kookmin Bank reported a breach involving 119 customers.
Recommended For You
![]()
![]()
![]()
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Register for free to keep reading.
Create a free account to get unlimited breaking news and alerts when your stocks move.
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.