Cyberattacks on South Korean Banks Involving ARTEX AI and Claude AI
A Chinese-speaking threat actor initiated a series of cyberattacks against multiple South Korean banking institutions earlier this month, leveraging the ARTEX AI penetration testing framework and Claude agents.
A Chinese-speaking threat actor initiated a series of cyberattacks against multiple South Korean banking institutions earlier this month, leveraging the ARTEX AI penetration testing framework and Claude agents.
The attacks compromised sensitive client data, including personal information and credit card details, while also triggering operational disruptions at some affected organizations. The South Korean government convened an emergency response session and issued urgent directives to enhance security protocols for critical IT infrastructure.
Security firm CrowdStrike confirmed the deployment of ARTEX AI, a penetration testing suite previously available as open-source software developed in China.
Researchers analyzing the attacker’s infrastructure discovered exposed directories containing Claude Code session logs, ARTEX configuration files, and Claude memory data. The ARTEX instance utilized DeepSeek v4.1-flash as its primary large language model (LLM) backend, with the threat actor integrating additional models such as GLM-5.3 (Zhipu AI) and Grok 4.6 to support Claude Code operations.
Investigators noted that the attacker likely accessed DeepSeek through the API proxy or reseller service xcai[.]pro.
These findings provided insights into the actor’s methodology, with target lists aligning with previously documented financial sector breaches, enabling high-confidence correlation. The attacker’s use of AI tools to generate resumes also revealed personal details, including identification information, contact data, and a Telegram account.
Based on resume data, CrowdStrike suggested the attacker may be a 26-year-old individual from Maoming, Guangdong, China, who studied at the South China University of Technology.
However, discrepancies in the provided date of birth—listed as 2007—raised doubts about the reliability of these details. The stolen data from South Korean banks was not explicitly targeted for monetization, as the attacker requested assistance from Claude in identifying Telegram-based groups for selling Korean-specific data.
Following confirmation of ARTEX AI’s real-world deployment, the project’s developers transitioned the framework to a closed-source model and halted further updates.
Despite this, the existing codebase has been repurposed to create localized versions in English and Korean, ensuring its continued availability in modified forms. The incident underscores the growing risks associated with AI-driven cyber operations and highlights the need for robust defensive measures against evolving threat landscapes.
“CrowdStrike suggested the attacker may be a 26-year-old individual from Maoming, Guangdong, China, who studied at the South China University of Technology.”
