A hacker used ARTEX AI and Claude agents to attack Korean banks
The hacker left open directories with Claude Code session histories, and these records let CrowdStrike connect the attack to the bank breaches.
A hacker who speaks Chinese used ARTEX AI and Claude agents to attack South Korean banks this month. The targets included Shinhan Bank, KB Kookmin Bank and Hana Bank. The attack exposed client personal data and credit card information, and some systems stopped. CrowdStrike says that the attacker used ARTEX AI. The government held an emergency meeting.
What happened
The attacker targeted many banks. Some systems stopped, and client data was exposed. The government said that critical IT systems must have security measures immediately.
The tools
ARTEX AI is a penetration test suite made in China. It was open-source until a short time before this. CrowdStrike says that the attacker used these LLMs (large language models):
- DeepSeek v4.1-flash, as the primary backend
- GLM-5.3, for more Claude Code sessions
- Grok 4.6, for more Claude Code sessions
How researchers found the link
The researchers found open directories on the infrastructure of the attacker. They contained Claude Code session histories, ARTEX configuration files and Claude memory files. The targets were the same as in reports of breaches before this.
What is not known
The attacker used the same tools to make a résumé. CrowdStrike says that the personal data in it can be of the attacker, but it is not sufficient to show who the attacker is. The ARTEX developer made the project closed-source and stopped updates, but derivatives of the code are available.
Sources
- Hacker used ARTEX AI and Claude agents to target South Korean banksbleepingcomputer.com
Posted