Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
CrowdStrike has identified an intrusion campaign against South Korean financial institutions conducted between late September and early October 2026. The attacker used ARTEX, an open-source penetration testing tool developed in China, orchestrating multiple LLM models to automate reconnaissance, exploitation, and exfiltration. The result: personal data of approximately 68,000 people exposed, a team of 28 investigators mobilized, and the first public statement by a head of state on the threat of AI-assisted hacking in the banking sector.
- The threat actor employed ARTEX with a DeepSeek v4.1-flash backend, supplemented by GLM-5.3 and Grok 4.6 via Claude Code sessions, leaving configuration documents and Chinese-language prompts on an exposed instance.
- CrowdStrike attributes the activity with moderate confidence to a financially motivated Chinese-speaking actor, based on the Chinese-developed tool, Chinese-language prompts, and personal details surfaced in a Claude Code session.
- Affected banks confirmed differentiated exposures: Shinhan Bank roughly 25,000 customers, Yegaram Savings Bank roughly 40,000, KB Kookmin Bank 119 customers, Hana Bank 89 customers, for a total that sources place between roughly 65,000 and 68,000 individuals.
- South Korean President Lee Jae Myung publicly stated that "signs have emerged" of AI use in the attacks, while the Financial Services Commission issued a consumer alert on October 6, 2026.
ARTEX: How the Agentic AI That Automated the Attack Works
ARTEX was released on GitHub in 2026 by a security engineer using the handle 'Autumn'. The tool implements an agentic architecture: an orchestrator that coordinates LLM models to execute offensive sequences autonomously, with feedback loops between reconnaissance, vulnerability discovery, and exploitation phases.
In the South Korean campaign, researchers identified DeepSeek v4.1-flash as the primary LLM. Zhipu AI's GLM-5.3 and Grok 4.6 were employed in supplementary Claude Code sessions. This multi-model configuration enables specialized task distribution: one model for scanning, another for payload generation, a third for post-exploitation analysis.
Technical evidence was recovered from an exposed ARTEX instance on a single IP address, which also hosted an open directory containing Claude Code session files. One document contained a Chinese-language prompt instructing the LLM on how to conduct pentesting activities. The use of multiple models and their integration with an open-source framework represents a qualitative leap over the isolated use of generic chatbots to write scripts.
The Traces the AI Left Behind
The paradox of the operation lies in its digital footprint. Advanced automation did not eliminate attributive traces; it multiplied them and made them more readable. The Claude Code files contained explicit queries to find "Korean data selling Telegram groups," indicating direct financial motivation. The same session surfaced personal details: Telegram username YY520CN, age 26, education at South China University of Technology, location Maoming in Guangdong province.
A second IP, located in Hong Kong, was identified as primary infrastructure controlled by the attacker. The concentration of evidence on a few exposed nodes—rather than a distributed command-and-control network—suggests an operator who underestimated the residual visibility of agentic tools, or lacked the skills to sanitize it.
CrowdStrike formulated its "moderate confidence" assessment with precise wording: "this assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts." Attribution to a "Chinese speaker" does not equate to confirmed citizenship or links to government APT groups.
"Signs have emerged suggesting AI agents were deployed in at least some of the attacks. It's now become possible to use AI to hack with ease even without specialized skills."
— President Lee Jae Myung, October 6, 2026
The Victim Count and Institutional Mobilization
The affected financial institutions released partial, non-uniform figures. Shinhan Bank confirmed exposure of roughly 25,000 customers; Yegaram Savings Bank roughly 40,000. KB Kookmin Bank reported 119 customers, though Rescana reported a different figure—119,000 for credit card data—that finds no corroboration in converging primary sources. Hana Bank confirmed 89 exposed customers.
The combined total ranges between roughly 65,000 and 68,000 individuals, according to Tech Insider and The Record. This discrepancy reflects the ongoing state of the banks' internal investigations, still in the reconciliation phase.
On the investigative front, the National Office of Investigation created a dedicated team of 28 investigators. The Financial Supervisory Service identified 33 IP addresses used in the attacks, linked to at least 12 countries. This geographic distribution of indicators does not necessarily imply the attacker's physical presence in all jurisdictions; it may reflect the use of proxied infrastructure, compromised VPS, or resold hosting services.
Why It Matters
The brief does not document specific remedial measures issued by South Korean authorities or the affected banks. The Financial Services Commission issued a consumer alert, but the dossier does not specify the operational content of that communication.
The source does not clarify whether AI use has been technically proven by South Korean authorities or remains an investigative hypothesis. President Lee spoke of "signs emerged"; Chairman Lee Eog-weon stated that "the possibility of hacking attacks using AI cannot be ruled out." This institutional caution contrasts with CrowdStrike's more definitive reading, which has direct access to technical artifacts.
The dossier does not specify whether exfiltrated data has actually been sold or used for secondary fraud. No infrastructure overlaps emerge linking the actor to Chinese government APT groups such as Volt Typhoon or Flax Typhoon. The precise initial access method—exploit, credential stuffing, or other vector—is not documented in the brief.
The case raises questions that transcend the single incident. The use of open-source agentic tools lowers the skill barrier for conducting scalable offensive operations, but leaves a richer attributive profile than traditional attacks. Whether this exposure is operational error or an implicit mechanism of the technology remains an open question.
Frequently Asked Questions
Who is the attacker?
CrowdStrike assessed with moderate confidence that it is a financially motivated Chinese-speaking actor. The dossier contains personal details surfaced in a Claude Code session—a 26-year-old man from Maoming, Guangdong—but an interlocutor contacted at the associated number denied any involvement. It is not confirmed whether these data are authentic or actually identify the operator.
Has AI use been technically proven?
South Korean authorities have adopted cautious formulations. President Lee referred to "signs emerged"; the Financial Services Commission Chairman spoke of a possibility that cannot be excluded. CrowdStrike documented the use of ARTEX and Claude Code sessions with Chinese-language prompts, but convergence between technical analysis and institutional position is not yet complete.
What is the risk for exposed customers?
The dossier does not specify the exact nature of the stolen data nor whether it has already been used for fraud. The variability in figures across sources—roughly 65,000-68,000 individuals total—reflects an investigation still in progress.
Sources
- https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
- https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge
- https://www.koreatimes.co.kr/amp/southkorea/law-crime/20261008/chinese-speaking-hacker-possibly-linked-to-ai-driven-attacks-on-s-korean-banks-report
- https://www.koreajoongangdaily.com/business/chinesespeaking-hacker-possibly-behind-attack-on-korean-banks-crowdstrike-says/12910498
- https://www.rescana.com/post/ai-powered-cyber-attacks-target-major-south-korean-banks-october-2026-data-breach-analysis-and-response
- https://therecord.media/south-korean-bank-hacks-ai-agents
- https://tech-insider.org/south-korea-ai-bank-hacking-investigation-2026/
- https://news.az/news/crowdstrike-claims-china-based-suspect-used-ai-tools-in-s-korean-bank-hacks
- https://www.cisa.gov/news-events/news/cisa-national-cyber-security-centre-ncsc-uk-and-global-partners-issue-advisory-chinese-government
- https://www.rapid7.com/blog/post/tr-new-whitepaper-stealthy-bpfdoor-variants/
- https://www.rapid7.com/blog/post/tr-bpfdoor-telecom-networks-sleeper-cells-threat-research-report/
Information verified against cited sources and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.