CrowdStrike Says AI Tools Were Used in Attacks on South Korean Banks
AI tools were reportedly used as part of a cyberattack campaign targeting South Korean financial institutions, according to cybersecurity firm CrowdStrike. The campaign, active from late September to early October, involved a suspected financially motivated threat actor using the Chinese-developed ARTEX agent alongside Anthropic’s Claude Code. CrowdStrike identified evidence of the tools in attacker-controlled infrastructure and said the activity targeted multiple South Korean financial organisations. The findings add to growing concerns that AI agents could allow attackers to conduct intrusions faster and at greater scale.
AI Agents Become Part of the Attack Chain
CrowdStrike’s investigation found ARTEX configuration files, Claude Code session histories and Claude memory files on infrastructure linked to the campaign. ARTEX is an open-source agentic penetration-testing tool developed in China. While designed for legitimate security testing, the investigation indicates that it was used alongside large language models during the attacks.
The attacker reportedly used ARTEX with DeepSeek as its primary model, while also using other AI models for additional Claude Code sessions. CrowdStrike said the combination of agentic AI and traditional offensive techniques allowed the threat actor to carry out activity against several organisations within a relatively short period.
South Korean Financial Institutions Targeted
The campaign targeted South Korean financial organisations and resulted in data being exfiltrated, although CrowdStrike said the total number of affected organisations remained unconfirmed in its investigation.
The wider cyber campaign had already prompted concern among South Korean authorities. Earlier reports said several major banks, including Shinhan Bank, KB Kookmin Bank, Hana Bank and Woori Bank, had experienced cyber intrusions or data breaches. South Korean regulators subsequently called on financial institutions to strengthen their cybersecurity measures.
Suspect Believed to Be Chinese-Speaking
CrowdStrike assessed with moderate confidence that the threat actor was likely a Chinese speaker and financially motivated. The company found Chinese-language prompts and other clues in the attacker’s AI-related activity.
CrowdStrike also identified personal information in one Claude Code session that appeared to point toward a possible 26-year-old individual from Guangdong, China. However, the cybersecurity firm stressed that the available information was not sufficient to definitively associate those details with the person behind the attacks. The campaign has not been attributed to a named threat group.
What the Campaign Signals for Cybersecurity
The incident highlights a shift in how AI can be incorporated into cyberattacks. Rather than being limited to tasks such as generating text or assisting with basic coding, agentic AI systems can potentially support multiple stages of offensive activity.
CrowdStrike expects adversaries to continue experimenting with AI tools to increase their operational speed and capabilities. The South Korean attacks therefore offer another example of the growing challenge for financial institutions as attackers combine traditional intrusion techniques with increasingly capable AI systems.
