SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
CrowdStrike finds AI-driven hacks on South Korean banks

CrowdStrike finds AI-driven hacks on South Korean banks

Thu, 8th Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

CrowdStrike identified a targeted cyber campaign against South Korean financial organisations that resulted in data exfiltration. The activity used AI-driven tooling.

The campaign ran from late September to early October 2026 and involved infrastructure linked to intrusions at multiple organisations in the country's financial sector.

The analysis focused on attacker-controlled open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files. According to CrowdStrike, those materials provided a direct view of the intruder's methods and tools.

The attacker used ARTEX, an open-source agentic penetration testing tool developed in China, together with large language models. The activity has not been attributed to a named hacking group, but CrowdStrike assessed the operator was likely a Chinese speaker and financially motivated.

Infrastructure trail

CrowdStrike linked one server, at IP address 38.244.50[.]120, to the activity, saying it hosted an ARTEX instance and an open directory that included a Claude Code markdown file. That document contained a Chinese-language prompt outlining how the language model should carry out penetration testing tasks, the research found.

A Hong Kong-based IP address mentioned in the document led researchers to additional open directories. Those directories contained more Claude Code session histories, ARTEX files and memory files, which CrowdStrike said showed extensive use of ARTEX and language models against South Korean financial targets during the period.

The sessions indicated a two-server setup. In that arrangement, the Hong Kong-based infrastructure acted as the main attacker-controlled environment, while the 38.244.50[.]120 server hosted the ARTEX instance believed to have been used in the attacks on Korean organisations.

CrowdStrike said the ARTEX environment used DeepSeek v4.1-flash as its main language model backend. It added that the attacker also used GLM-5.3 from Zhipu AI and Grok 4.6 in other Claude Code sessions, and likely accessed DeepSeek through a proxy or reseller service.

Bank targets

Industry reporting cited in the research said several South Korean financial organisations were breached from late September 2026. At one bank, the attacker reportedly accessed a loan progress inquiry service used by financial brokers. At another, the attacker reportedly compromised an employee mobile work-support system.

The total number of affected organisations remains unconfirmed. CrowdStrike said some targeted entities matched those mentioned in broader industry reporting, and that multiple incidents appeared to involve overlapping IP addresses.

CrowdStrike also listed several proxy IP addresses that it said were used during the ARTEX-related activity. It identified 38.244.50[.]120 as a threat actor-controlled address tied to the campaign.

Sale of data

The session records also suggested an interest in monetising stolen information. CrowdStrike said the attacker asked Claude where threat actors typically sell Korean data breach information and sought help locating Korean Telegram groups used for data sales.

In one session, the user asked Claude to draft a security researcher résumé with bullet points describing results from the ARTEX-related activity. The prompt included personal details such as the name YY, a Telegram handle, an age, an education entry for South China University of Technology and a location in Maoming, Guangdong.

CrowdStrike said the same Telegram username appeared in Claude Code sessions tied to vulnerability research involving a Telegram-based NFT gift marketplace. It also said an unknown threat actor used that username in activity targeting a possible Chinese payment platform, although the available information did not allow definitive identification.

The findings point to a more direct use of AI systems in hands-on intrusion work, rather than only for peripheral tasks such as drafting text or translation. CrowdStrike said the combination of agentic AI tools and established offensive methods showed evolving attacker tradecraft and enabled a financially motivated actor to carry out multiple intrusions in a short period.

CrowdStrike expects adversaries to keep experimenting with AI tools in their operations to speed up their activity.