South Korean Banks Fall Prey to Sophisticated Cyberattacks, AI Suspected
In a disturbing trend that’s sending shockwaves through the cybersecurity community, South Korea’s banking sector is facing a wave of high-profile cyberattacks, with authorities suspecting that artificial intelligence (AI) was used in some of these incidents. President Lee Jae Myung confirmed that there are indications of AI involvement, and police have launched a thorough investigation to uncover the full extent of the breaches.
The attacks, which compromised customers’ personal information, appear to be the work of a financially motivated threat actor with a sophisticated toolkit. CrowdStrike’s analysis revealed the presence of Claude Code session histories, ARTEX configuration files, and Claude memory files in the attackers’ infrastructure. While the exact AI tools used remain unclear, experts believe that a Chinese-speaking group is likely behind these attacks.
The use of AI in cyberattacks is a concerning development, as it allows threat actors to automate and scale their operations with greater ease. This trend has significant implications for organizations across industries, emphasizing the need for robust cybersecurity measures and continuous monitoring. The South Korean government’s swift response to this crisis demonstrates its commitment to protecting citizens’ data and preventing future attacks.
In related news, a malware campaign dubbed PoeLLM has been making headlines in recent weeks. This botnet, which emerged in April 2026, targets exposed AI and open-source services to mine cryptocurrency and expand its reach. Infected machines extract four keywords from a poem hosted on GitHub and use them to determine the IP address of the command-and-control server. The operator, who appears to be Italian-speaking, has updated the poem 11 times, demonstrating a high level of sophistication.
The PoeLLM botnet’s reliance on a poem for communication is an unusual tactic that highlights the creativity and adaptability of threat actors. This campaign serves as a reminder that cybersecurity teams must remain vigilant and prepared to face new and evolving threats.
In other developments, a jury has convicted Jonathan Spalletta, 36, of Maryland, of computer fraud and money laundering in connection with two high-profile hacks of decentralized crypto exchange Uranium Finance. The case involves the abuse of smart contract flaws to steal millions of dollars, which were then laundered through various cryptocurrency transactions.
This conviction serves as a warning to threat actors that their activities will be closely monitored and prosecuted. As cybersecurity regulations continue to evolve, it’s essential for organizations to prioritize robust security measures and incident response plans to mitigate the impact of future attacks.
In light of these incidents, it’s crucial for individuals and businesses alike to take proactive steps in securing their online presence. This includes implementing strong passwords, enabling two-factor authentication, and staying informed about emerging threats and best practices. By doing so, we can work together to prevent such sophisticated cyberattacks from succeeding in the future.
Source: SecurityWeek — 2026-10-09