A Chinese-speaking hacker used an open-source AI agent tool alongside Anthropic's Claude Code and other chatbots to breach South Korean banks in a campaign that ran from late September into early October, according to research from the cybersecurity firm CrowdStrike.
CrowdStrike said the attacker relied on a recently released tool called ARTEX AI, an agentic penetration-testing suite built in China that does not run its own language model but instead connects to outside ones. In the observed intrusion, ARTEX used DeepSeek's V4.1-Flash model as its primary backend, likely accessed through a third-party API reseller, while the attacker separately ran Claude Code sessions and used Zhipu AI's GLM-5.3 and xAI's Grok 4.6 for other parts of the operation, researchers found.
Shinhan Bank has said information tied to roughly 25,000 customers was compromised, while KB Kookmin Bank reported a smaller leak affecting 119 customers, including data from a loan-inquiry service used by outside brokers. The intrusions also caused system outages at some institutions. South Korea's government held an emergency meeting afterward and called for immediate security upgrades at financial and other critical IT systems, according to reporting from BleepingComputer.
CrowdStrike said it pieced the operation together after finding open, unsecured directories on attacker-controlled servers that contained Claude Code session histories, ARTEX configuration files and AI "memory" files the attacker had generated. One file, an AI-written résumé exposed in the same directories, included a Telegram handle and contact details; CrowdStrike said with moderate confidence that the attacker may be a 26-year-old from Maoming, in Guangdong province, who studied at South China University of Technology, though a phone number listed reached someone who denied any involvement.
Loophole exploited, then closed
The chat logs show no clear plan to sell the stolen records; the records indicate the attacker asked Claude where Korean financial data could be sold and whether Telegram groups existed for that purpose, suggesting the operation may still have been financially motivated even without a monetization plan in place yet. After the real-world misuse came to light, ARTEX's developer took the project closed-source and halted further updates — though copies of its earlier code are already circulating as English- and Korean-language derivatives, limiting how much the move will contain the tool's spread.
The case adds to a run of incidents this year in which commercial and open-source AI coding agents have been repurposed for intrusion rather than defense, a trend security researchers have flagged as agentic tools become cheap and capable enough to automate steps that once required a skilled human operator. CrowdStrike has not formally attributed the campaign to a named hacking group, and Anthropic had not commented publicly on the attacker's use of Claude Code at the time of CrowdStrike's initial reporting.
South Korean regulators are expected to require banks to tighten monitoring of unusual API and database queries, the kind of activity AI-driven reconnaissance tools generate at high volume. For now, CrowdStrike says it continues to track variants of ARTEX circulating outside China, meaning the tool that hit Shinhan and KB Kookmin is unlikely to disappear even as its original author goes dark.