CrowdStrike Links China-Based Suspect to South Korean Bank Cyberattacks

CrowdStrike suspects a 26-year-old individual in China's Guangdong province of cyberattacks on South Korean financial institutions. The attacker allegedly used AI tools like ARTEX and Claude Code to target banks between late September and early October. CrowdStrike assessed with moderate confidence that the threat actor is a Chinese speaker motivated by financial gain.
CrowdStrike’s Wednesday report tied the suspected intruder to sessions involving AI coding tools and related infrastructure. The person reportedly asked Claude about where stolen Korean data is traded and how to locate Korean-language Telegram markets, and also requested a security-researcher résumé listing a Telegram handle, age, education, and Maoming, Guangdong.
ARTEX is described as an open-source automated penetration-testing agent released on GitHub this year by a Chinese engineer using the name Autumn. It links to outside models, including ChatGPT, Claude, and DeepSeek. South Korean authorities opened a probe after at least nine banks reported incidents; Shinhan Bank cited about 25,000 affected customers, while KB Kookmin Bank reported 119.
The alleged campaign could affect South Korean bank customers whose personal data may be exposed, potentially increasing risks of fraud or targeted phishing. Financial institutions may reassess defenses against AI-assisted intrusion attempts, while investigators could face cross-border coordination challenges. The involvement of widely accessible coding assistants may also prompt broader discussion about safeguards, monitoring, and responsible use of AI tools in cybersecurity. The impact remains uncertain, as attribution is assessed with moderate confidence and the probe is ongoing.