South Korean lenders are sorting through the aftermath of an automated cyberattack run using Anthropic's Claude Code and an open-source Chinese security toolkit called ARTEX AI. The breach hit major institutions across the country, including Hana Bank, Shinhan Bank, and KB Kookmin Bank, compromising customer records and taking some services offline.
The intrusion prompted an emergency government session in Seoul to demand immediate safeguards for critical financial infrastructure. Now, findings published by cybersecurity firm CrowdStrike show just how heavily the perpetrator relied on generative tools to do the heavy lifting.
Unsecured Logs Exposed the Whole Operation
CrowdStrike tracked down the attacker's infrastructure after the intruder left open directories exposed to the internet. Those unprotected servers contained raw configuration files, Claude memory entries, and extensive Claude Code session transcripts.
According to CrowdStrike, the automated workflow ran on ARTEX AI, a penetration testing utility created in China that operated as open source until recently. The attacker configured ARTEX to use DeepSeek v4.1-flash as its core engine, likely routed through an application programming interface reseller called xcai[.]pro. To drive Claude Code sessions, the operator also pulled in Grok 4.6 and Zhipu AI's GLM-5.3.
The session histories revealed that the attacker breached the banks without a clear monetization scheme in place. Claude transcripts show the hacker asking the model to locate Telegram groups that trade in stolen Korean data.
Clues Left in a Generated Résumé
The attacker's reliance on generative software also undermined their operational security. Investigators discovered a curriculum vitae generated with the same toolset, which contained identity details, contact information, and a Telegram handle.
The résumé pointed to a 26-year-old Chinese national living in Maoming, Guangdong, who had studied at the South China University of Technology. Researchers pointed out that another field listed a 2007 birthdate, meaning the details may belong to someone else or represent fabricated information.
Following proof that the software assisted actual financial intrusions, ARTEX's maintainer pulled the public repository and stopped all future updates. But the utility is not gone. Other developers had already copied the code into Korean and English forks that remain active across the web, leaving institutions to defend against automated intrusions that move faster than manual investigations.
ADFiled by The AI Desk
Models, assistants and the companies and chips behind them, reported from what was released and what was claimed, with the difference kept clear.
More from this desk →
Be the first to comment
Join the argument. No password, just your email or a passkey.