Lone Hacker Used AI Pentest Tool on South Korean Banks

U.S. cybersecurity firm CrowdStrike said in a report published Wednesday that a string of attacks on South Korean banks over the past two weeks was likely the work of a single 26-year-old attacker. The report places the suspect in Maoming, in China's Guangdong province, acting for financial gain with an open-source AI penetration-testing tool called ARTEX, built by a Chinese developer, paired with several large language models to handle reconnaissance, scanning and intrusion. CrowdStrike rated its own assessment "moderate confidence."

Since late September, at least nine South Korean financial institutions have disclosed breaches or been reported on by local media. Shinhan Bank's loan-agency inquiry system was hit for three straight days, exposing the names, phone numbers, annual income and loan amounts of 25,729 customers. KB Kookmin Bank and Hana Bank each had customer data leaked for 119 and 89 people respectively, while BNK Busan Bank reported 11 employees' information exposed.

How the attacker's identity slipped out

CrowdStrike's trail started with AI coding-tool sessions and servers the attacker left behind. According to the report, the suspect had asked Claude to draft a resume that included a messaging-app handle, age, education background and Maoming as a location. Researchers also found a large volume of Chinese-language prompts in the sessions.

The attack chain itself wasn't technically novel. What got breached were peripheral systems — loan-agency platforms, employee business systems and external-partner systems — with no reported damage to core account systems so far. On the tooling side, ARTEX was published on GitHub this past July to automate reconnaissance, vulnerability scanning and attack-path planning. The report says the attacker's primary model was DeepSeek v4.1-flash, backed up by GLM-5.3 and Grok 4.6, with some operations carried out through Claude Code sessions.

"This allows one human to target many customers in a very short period of time using the power of AI."

(CrowdStrike intelligence chief Adam Meyers, on how AI lets one person hit many victims at once.)

Anthropic and South Korean police did not respond to requests for comment. Chinese foreign ministry spokesperson Mao Ning said she wasn't familiar with the specifics and that China opposes hacking "in all its forms." Some reports say South Korea's Financial Security Institute traced the attack traffic to IP addresses spread across 12 countries and regions, though that detail hasn't been confirmed in any official document so far.

Regulators are shoring up the edges first

South Korea's financial regulators have told banks to audit vulnerabilities in internet-facing systems, tighten authentication and access controls for external-partner accounts, and block access from overseas IP addresses. Those measures target exactly the opening this attack exploited: loan-agency platforms and outsourced operations systems are typically built by third parties, run with broad permissions and patched slowly.

What it means for Chinese AI and security teams

In this case, the tool was a domestically built open-source project, the primary models were DeepSeek and GLM, and the suspect's location points back to China. For teams building large-model APIs and open-source security tools in China, the pressure lands in two places.

First is abuse detection on the API side. Several overseas model vendors already publish abuse reports on a regular basis — Anthropic disclosed last November that a group it called GTG-1002 had used Claude Code to automate attacks on roughly 30 targets. Domestic vendors rarely publish anything comparable, and with DeepSeek v4.1-flash now named as the primary model in this case, it's a natural question how much visibility its usage monitoring actually has.

Second is how open-source pentesting tools get released. Tools like ARTEX have legitimate uses in security testing, and the code is sitting on GitHub for anyone to download. Whether hosting platforms respond to this string of Korean cases by adding usage terms or access gates to this category of project remains to be seen.

Sources: Reuters, The Korea Times, The Decoder, CocoLoop, The Elec; suspect profile, tools and model list verified against the CrowdStrike report, affected-customer counts verified against Korean media.