26-Year-Old In China Suspected In South Korea Bank Cyberattacks, CrowdStrike Says

Date:

A 26-year-old based in China’s Guangdong province may be behind a recent wave of cyberattacks targeting South Korea’s financial sector, according to US cybersecurity firm CrowdStrike.

In a report published on Wednesday, CrowdStrike said it uncovered personal details linked to the suspected attacker while analysing sessions involving AI coding tools and infrastructure connected to a campaign targeting South Korean financial institutions from late September to early October.

The suspected attacker allegedly used ARTEX, a Chinese-developed open-source AI agent designed for automated penetration testing, alongside Anthropic’s Claude Code. CrowdStrike said the activity had not been attributed to a named threat actor but assessed with moderate confidence that the individual was a Chinese speaker and financially motivated.

The cybersecurity firm said the assessment was based partly on the use of ARTEX and Chinese-language prompts observed during the AI sessions. The individual also reportedly asked Claude where cybercriminals typically sell stolen South Korean data and sought information about Korean Telegram groups involved in data sales.

In another session, the person allegedly asked Claude to create a security researcher résumé containing details including a Telegram account, age, educational background and a location in Maoming, Guangdong. CrowdStrike said the information likely belonged to the suspected attacker. A man who answered a phone number included in the report denied having any knowledge of the matter.

The case is expected to add to growing concerns about the use of AI agents in cyberattacks and whether organisations are adequately prepared to defend against them. ARTEX itself is not a standalone AI model but connects to external large language models, including ChatGPT, Claude and DeepSeek, to help users identify network vulnerabilities. Its GitHub page states that it is intended for personal learning, code research and local technical verification, rather than attacks against real-world online systems.

At least nine South Korean banks have reportedly been targeted by cyberattacks since late September, prompting police to launch an investigation. Shinhan Bank said about 25,000 customers had their personal information compromised, while KB Kookmin Bank reported that the personal information of 119 customers had been leaked.

Anthropic, South Korean police and China’s foreign ministry had not immediately responded to requests for comment.

Share post:

Popular

More like this
Related

Seven Women Arrested In Ghana Over Cash Bouquets And Cakes Made From Banknotes

Authorities in Ghana have arrested seven women accused of...

Ahmad Zahid, AG Get Green Light To Appeal Ruling On Yayasan Akalbudi Case

UMNO president Datuk Seri Ahmad Zahid Hamidi and the...

Three Siblings Killed In Motorcycle-Lorry Crash On Way To School In Pontian

Three siblings were killed after the motorcycle they were...

Indonesia Government Sued Over Failure To Tackle Borneo Forest Fires And Haze

The Indonesian government is facing legal action over allegations...