South Korean Banks Hit with Sophisticated Cyberattacks Using AI-Powered Tools
A devastating wave of cyberattacks has shaken the South Korean financial sector, leaving multiple banks reeling from data breaches and system outages. The attacks, which targeted prominent institutions such as Shinhan Bank, KB Kookmin Bank, and Hana Bank, were carried out by a Chinese-speaking hacker using advanced AI-powered tools.
The attacker leveraged ARTEX AI, an open-source penetration testing suite developed in China, to gain unauthorized access to the banks’ systems. This was done through Claude agents, which are essentially software “bots” that interact with the ARTEX platform to execute specific tasks. The use of these tools highlights the growing threat of AI-powered attacks on financial institutions.
The extent of the damage is alarming, with the attacker exposing clients’ personal data and credit card information, causing system outages in some cases, and leaving a trail of compromised security measures in its wake. In response to the crisis, the South Korean government convened an emergency meeting to discuss immediate security measures for critical IT systems.
Security researchers from CrowdStrike have been analyzing the attacker’s infrastructure and have uncovered crucial evidence pointing to the use of ARTEX AI. They found open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files. The records revealed that the threat actor used a combination of LLM (Large Language Model) backends, including DeepSeek v4.1-flash, GLM-5.3 (Zhipu AI), and Grok 4.6 for additional Claude Code sessions.
What’s particularly concerning is that the attacker demonstrated a sophisticated understanding of how to use these tools, even going so far as to create a résumé using Claude to gather identification, contact, and Telegram account details. The attack raises questions about the ability of AI-powered tools to be used for malicious purposes and highlights the need for robust security measures.
In the aftermath of the attacks, ARTEX AI’s developer announced that it would be making the project closed-source and discontinuing further updates in response to its use in real-world attacks. However, this move does little to mitigate the risks posed by existing code derivatives, which remain available online in both English and Korean languages.
This incident serves as a stark reminder of the evolving threat landscape and the need for financial institutions to prioritize robust security measures and stay ahead of emerging threats. As AI-powered tools continue to play an increasingly significant role in cybersecurity, it is essential that organizations invest in developing the necessary expertise and infrastructure to combat these sophisticated attacks.
To mitigate similar risks, we recommend that financial institutions:
* Regularly update their security software and plugins
* Implement robust access controls and monitoring systems
* Educate employees on AI-powered attack vectors
* Develop incident response plans for data breaches
By taking proactive steps to address the threat of AI-powered attacks, organizations can better protect themselves against these sophisticated threats.
Source: Bleeping Computer — 2026-10-10