A 26-year-old man believed to be based in China’s Guangdong province may be behind a recent series of cyberattacks targeting South Korean financial institutions, according to cybersecurity firm CrowdStrike.

In a report published Wednesday, CrowdStrike said it identified personal information potentially linked to the suspected attacker while examining sessions from AI coding tools and infrastructure connected to attacks against South Korean financial institutions between late September and early October.

The suspected attacker reportedly used ARTEX, a Chinese-developed open-source AI penetration-testing tool, together with Anthropic’s Claude Code and other large language models. CrowdStrike said the activity has not been attributed to a specific known threat actor but assessed with moderate confidence that the person is likely a Chinese speaker and financially motivated.

The company based its assessment partly on the use of the Chinese-developed ARTEX tool and Chinese-language prompts observed during the AI sessions.

CrowdStrike said the individual also asked Claude where threat actors typically sell stolen South Korean data and sought information about Korean Telegram groups involved in selling leaked data. In another AI session, the person reportedly asked Claude to create a security researcher resume containing details including a Telegram account, age, educational background and a location in Maoming, a city in Guangdong.

CrowdStrike said the information likely belonged to the attacker, although a man who answered a phone number included in the company’s report denied knowing anything about the case.

ARTEX is an open-source AI agent designed for automated penetration testing. The tool was released on GitHub this year by a Chinese security engineer using the handle Autumn. Rather than operating as its own large language model, ARTEX connects to external AI models such as ChatGPT, Claude and DeepSeek to help organizations identify vulnerabilities in their networks.

READ
Denmark’s CPR Data Breach Exposes Personal Information of 8.8 Million People

The project’s GitHub page says ARTEX is intended for personal learning, code research and local technical verification and warns users not to use it for real-world testing against online systems or websites.

The case highlights growing concerns about AI agents being used to automate cyberattacks. Security researchers and governments are increasingly examining how autonomous AI tools can perform reconnaissance, identify vulnerabilities and assist with other stages of an attack.

At least nine South Korean banks have reportedly disclosed or been targeted in cyberattacks since late September. The incidents have prompted South Korean police to launch an investigation, while President Lee Jae Myung has called for stronger measures in response to the attacks.

Shinhan Bank said about 25,000 customers had their personal information compromised, while KB Kookmin Bank reported that personal information belonging to 119 customers had been leaked.

CrowdStrike’s findings have not been independently confirmed, and the company has not publicly attributed the campaign to a named threat group. Anthropic, South Korean police and China’s foreign ministry had not immediately responded to requests for comment.


Buy ExpressVPN with PayPal or Credit Card

Advertisement