cd /news/ai-safety/chinese-speaking-hacker-possibly-lin… · home › topics › ai-safety › article
[ARTICLE · art-147261] src=koreaherald.com ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report

CrowdStrike reported Wednesday that an unidentified, likely Chinese-speaking, financially motivated attacker used the open-source AI penetration-testing tool ARTEX and large language models to breach multiple South Korean financial institutions between late September and early October, stealing data. The compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees, according to CrowdStrike, which said the attacker primarily used DeepSeek v4.1-flash supplemented by GLM-5.3 and Grok 4.6 through Claude Code sessions. The attacker's identity, the full extent of the breaches and the amount of stolen data remain unconfirmed, CrowdStrike said, adding that the assessment of a Chinese speaker is made with moderate confidence based on ARTEX and observed Chinese-language prompts.

read2 min views1 publishedOct 8, 2026
Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report
Image: Koreaherald (auto-discovered)

US cybersecurity firm CrowdStrike said an unidentified hacker believed to be a Chinese speaker used artificial intelligence-powered hacking tools to breach multiple South Korean financial institutions and steal data.

In a report released Wednesday, CrowdStrike said the attacker used ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models to carry out cyberattacks between late September and early October.

The findings come amid a series of data breaches at South Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank, prompting financial authorities and investigators to launch probes into the incidents.

According to CrowdStrike, the compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees.

"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in the report.

"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts."

The cybersecurity firm said the attacker primarily used DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6 through Claude Code sessions.

In one Claude Code session, the attacker asked Claude to draft a security researcher resume using personal details, including an age of 26 and an educational background at South China University of Technology in Guangdong, China.

However, the attacker's identity, the full extent of the breaches and the amount of stolen data remain unconfirmed.

CrowdStrike also identified two servers used in the attacks: one based in Hong Kong serving as the attacker's primary infrastructure and another hosting ARTEX, which was likely used to target South Korean financial institutions.

An analysis of files showed the attacker asked Claude about marketplaces for stolen South Korean data and Telegram groups involved in selling such information, suggesting a possible financial motive. (Yonhap)

── more in #ai-safety 4 stories · sorted by recency
── more on @crowdstrike 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/chinese-speaking-hac…] indexed:0 read:2min 2026-10-08 · —