UPDATE
CrowdStrike traces the Korean bank hacks to a likely Chinese-speaking attacker using AI agents
What changed: CrowdStrike published its own technical report, saying it recovered the attacker’s session logs. The open-source tool ARTEX ran mainly on DeepSeek v4.1-flash, and the attacker also worked in Anthropic’s Claude Code, using Zhipu’s GLM-5.3 and xAI’s Grok 4.6 in some sessions.
The firm said the campaign ran from late September to early October and stole data from South Korean financial organizations, and that the attacker asked Claude where Korean breach data is sold. “While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” CrowdStrike wrote.
Reuters counts at least nine South Korean banks that have disclosed or been reported as targeted since late September.