AI-Powered Hackers Used ARTEX and Claude to Target South Korean Banks
Chinese-speaking hackers used the ARTEX AI penetration-testing suite and the Claude agent to launch a cyberattack against South Korea’s financial industry earlier this month, according to security researchers.
The attackers targeted multiple South Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. The campaign exposed customers’ personal data and credit card information and reportedly caused system outages in some cases.
South Korea’s government responded by holding an emergency meeting and calling for urgent security measures to protect critical information technology systems.
Attackers used ARTEX AI and multiple large language models
Researchers identified the attackers’ infrastructure and discovered an open directory containing Claude Code session history, ARTEX configuration files, and Claude memory files. The records provided insight into the attackers’ activities and showed that their targets overlapped with those cited in previous reports of financial-sector breaches, helping researchers establish a reliable link.
“The ARTEX instance used DeepSeek v4.1 Flash as the primary LLM backend, and the attacker supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions,” CrowdStrike explained.
CrowdStrike researchers said the threat actor likely accessed DeepSeek through the LLM API proxy or reseller “xcai[.]professional.”
Security firm CrowdStrike recently acknowledged using ARTEX, an open-source agent penetration-testing suite developed in China. The incident is significant because it provides evidence that the AI-powered tool was used in a real-world cyberattack.
Attackers exposed their own personal information
The attackers also used the AI tool to create resumes. Those files reportedly exposed their IDs, contact information, and Telegram account details.
Based on information in one resume, CrowdStrike said the attacker may be a 26-year-old Chinese national who studied at South China University of Technology and lives in Maoming City, Guangdong Province, China.
However, researchers found that the attacker initially provided a 2007 date of birth. Although the personal information may belong to individuals involved in ARTEX-related activities, researchers said it is not reliable enough to confirm the threat actor’s identity.
Stolen bank data may have been offered for sale
Records showed that the attackers had no concrete plan to monetize the data stolen from South Korean banks. They asked Claude to pitch Telegram’s data-sales groups focused on South Korea instead.
ARTEX developer ends updates after real-world attack
After confirming that ARTEX had been used in real-world attacks, the developer announced that the project would become closed source and that further updates would stop.
However, the project’s current code, including its English and Korean derivatives, remains available in its current form.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



