AI Tools Helped a Suspected Chinese Hacker Breach South Korean Financial Firms
CrowdStrike has revealed that a suspected China-based threat actor used artificial intelligence tools to steal data from South Korean financial organisations. The campaign ran from late September to early October 2026. CrowdStrike assesses with moderate confidence that the attacker speaks Chinese and is financially motivated.
The attacker used ARTEX, a recently released open-source agentic pentesting tool developed in China, alongside Anthropic's Claude AI model. ARTEX was mainly used to find vulnerabilities and compromise specific services in victim organisations. The attacker also asked Claude to help find Korean Telegram groups that trade in stolen data, apparently to sell what they had taken. CrowdStrike noted that AI tooling can let a financially motivated attacker carry out multiple intrusions in a short time.
Researchers linked all the attacks to a single IP address. It hosted an ARTEX instance and an open directory containing a Chinese-language pentesting prompt for the AI model. The setup used several language models, including DeepSeek, GLM and Grok. A second, Hong Kong-based address held session histories and configuration files. One session included personal details, such as a Telegram username and a location in Guangdong, China, which CrowdStrike says likely belong to the attacker.