
What happened
CrowdStrike published an analysis on Oct 7 of a server used in attacks on South Korean financial institutions. It found traces of the open-source penetration-testing tool ARTEX and multiple LLMs, plus a Claude Code request containing a résumé that said the author was 26 and lived in Maoming, Guangdong.
Why it matters
At least 9 banks were publicly linked to the leaks, and CrowdStrike estimates with moderate confidence that the attacker is a Chinese speaker who was likely after money. The record shows he had asked Claude how to find places to buy and sell leaked South Korean data and Korean-language Telegram groups for sales.
What to watch
General availability starts Nov 4 in 12 countries.
WHO IT HITSThe findings land on bank security and fraud teams in South Korea handling breach disclosure, and on threat-intelligence analysts elsewhere trying to attribute attacks. They also matter to vendors of AI coding tools, whose usage logs can end up as forensic evidence.
Summaries like this, in your inbox every morning.
The attacks unfolded from late September into early October, when a series of data leaks struck multiple South Korean financial institutions. According to Reuters, at least 9 banks were identified as targets through victim disclosures and local news coverage. CrowdStrike investigated the campaign and found an openly browsable directory on a server linked to IP addresses used in the attacks. It contained Claude Code usage records and ARTEX configuration files, suggesting the attacker pursued targets between late September and early October that overlapped with the institutions already reported as victims.
The tooling points to a deliberately assembled setup. ARTEX, published on GitHub in 2026 by a Chinese security engineer, connects to external LLMs such as ChatGPT and Claude to hunt for vulnerabilities, letting the user choose which model to use. In this campaign the operator leaned on DeepSeek v4.1-flash, along with GLM-5.3 from Zhipu AI and Grok 4.6 from xAI. CrowdStrike says the attacker split work across two servers, using a Hong Kong-based server as the core of the attack infrastructure and another to run ARTEX, which also held Chinese-language documents instructing the linked LLMs on how to proceed. Activity was routed through nine additional proxy IP addresses.
CrowdStrike has not identified the attacker, estimating with moderate confidence that he is a Chinese speaker and likely motivated by money, based on his use of the Chinese-origin ARTEX and Chinese-language prompts. Adam Myers, who oversees attacker tracking and analysis at CrowdStrike, framed the case as an example of a human attacker using AI agents to attack at breadth, saying that AI has made it possible for one person to target many victims in a very short time. ARTEX's public page limits its use to personal study and code research and asks users not to run penetration tests against live systems or websites.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Anthropic kicked off the Anthropic Cyber Mission, providing frontier Claude models, on-site engineers and thre…

President Trump and leaders of major AI companies signed the White House Accord on Superintelligence, a volunt…

In a Fortune commentary piece, a media-and-culture professor argues that Anthropic researcher Jacob Coxon's vi…

CLEAR, a certified Qualified Anti-Terrorism Technology under the Department of Homeland Security, published a…

OpenAI said it disabled accounts behind Russia's "Dark Clark" operation, which used a fabricated researcher, M…

PwC Australia launched Cyber Managed Services, an AI-enabled cybersecurity service combining Google SecOps tec…
