A recent wave of cyberattacks has left the global cybersecurity community on high alert. One of the most concerning developments involves a series of bank breaches in South Korea that appear to have involved artificial intelligence (AI). The attacks, which compromised customers’ personal information, have led to an investigation by local authorities, who suspect AI was used in some capacity.
The suspected AI involvement has significant implications for the security community. As we’ve seen in recent years, AI-powered cyberattacks can be incredibly sophisticated and difficult to detect. If true, this would mark one of the most high-profile examples of AI being used in a real-world attack. The investigation is ongoing, but experts are already warning that the use of AI in cyberattacks could become more common.
The South Korean government has not revealed which AI tools were used or the full extent of the breaches. However, security firm CrowdStrike reported finding evidence of Claude Code session histories, ARTEX configuration files, and Claude memory files while analyzing the attack infrastructure. This suggests that a financially motivated threat actor may have been behind the attacks.
The use of AI in cyberattacks is not new, but it’s becoming increasingly prevalent. In recent years, we’ve seen AI-powered malware being used to carry out attacks on businesses and individuals alike. The sophistication of these attacks has forced security teams to rethink their approaches, as traditional detection methods may no longer be effective against AI-driven threats.
In other news, researchers have discovered a new form of malware called PoeLLM, which targets exposed AI and open-source services to mine cryptocurrency and expand its botnet. Infected machines extract four keywords from a poem hosted on GitHub and convert them into the IP address of the current command-and-control server. The operator has updated the poem 11 times, suggesting that they are actively using this tactic to evade detection.
The use of creative tactics like hosting malware in a poem is just one example of how threat actors are continually evolving their techniques. As security professionals, we must stay vigilant and adapt our defenses accordingly. This means staying up-to-date with the latest threats and technologies, as well as continuously monitoring our systems for signs of compromise.
In practical terms, this means that individuals and organizations should prioritize robust cybersecurity measures, including AI-powered detection tools and regular software updates. By doing so, we can better protect ourselves against these increasingly sophisticated attacks. As the use of AI in cyberattacks continues to grow, it’s clear that a more proactive approach to security is needed – one that anticipates threats before they even occur.
Source: SecurityWeek — 2026-10-09