Attackers used Chinese pentest tool ARTEX and language models against South Korean financial sector

The details that could expose a cybercriminal were not hidden in malware or network traces, but in a prompt: a request to create the résumé of a "security researcher." That is the starting point for the investigations firm CrowdStrike's…

A single red thread pulled out of a tangle of dark network cables, illustrating the forensic trace of a cyberattack.
Illustration
Gift article

Attackers used Chinese pentest tool ARTEX and language models against South Korean financial sector

The details that could expose a cybercriminal were not hidden in malware or network traces, but in a prompt: a request to create the résumé of a "security researcher." That is the starting point for the investigations firm CrowdStrike's new attribution of the attacks on South Korean financial institutions.

The US cybersecurity company CrowdStrike published a report on October 7 pointing to a possible perpetrator behind the recent weeks' cyberattacks on South Korea's financial sector: a 26-year-old individual who is reportedly located in Maoming, in China's Guangdong province. The identification rests largely on details revealed in a session with the AI coding tool Claude Code, according to the report as relayed by The Straits Times and Reuters. At the same time, CrowdStrike stresses that the information cannot definitively identify the attacker.

The attacks and the investigation

The report concerns a campaign against South Korean financial institutions from late September to early October. Several banks, among them Shinhan Bank and KB Kookmin Bank, have reported data breaches, and the authorities in Seoul are investigating attacks that hit multiple financial institutions. The police have not responded to inquiries from journalists, Reuters writes.

Politically, the case has received top-level attention. South Korea's President Lee Jae-myung said on Tuesday, October 6, that there were signs indicating that AI had been used in some of the hacking incidents, and called for heightened cybersecurity measures. The company has not published any quote from the president, and the CrowdStrike report has not itself been independently confirmed by sources other than the news agencies.

How the identification came about

The key to the attribution is said to lie in the analysis of AI coding sessions and infrastructure linked to the campaign. In one Claude Code session, the attacker is said to have asked for a résumé to be created for a security researcher, with the résumé describing results from the hacking activity itself. The prompt contained, according to CrowdStrike, information such as a Telegram account, age, educational background and a location in Maoming in Guangdong.

It is not the first time an AI tool has been associated with cybercrime, but it is unusual for an AI coding tool to leave behind this type of personal trace. Alongside this, CrowdStrike found that the same Telegram username appeared in other cyber activity, including vulnerability research against a Telegram-based NFT marketplace and a separate, suspected attack on a Chinese payment platform. It is this cross-reference that forms the basis for the link between the Claude Code session and the suspected actor.

The tools and the assessment

CrowdStrike writes that the attacker used ARTEX, a recently released, Chinese-developed open-source penetration testing tool, together with large language models. The company assesses with "moderate confidence" that the actor was a Chinese speaker and likely financially motivated.

What is confirmed – and what is not

The majority of the claims about the suspect come from CrowdStrike's own report, relayed through news agencies. The company said that the personal information likely belongs to the actor behind the activity, but at the same time warned that the available information cannot definitively identify the attacker. The sources relaying the report are near-identical, meaning they do not constitute independent confirmation.

It is also not known whether the identified individual is accessible to South Korean authorities, or whether any charges will be brought. The police in Seoul have not commented on the case. The question of whether an individual actually stands behind the attacks, or whether this is a mistaken attribution, remains open.

The significance of AI traces in cyber investigations

The case illustrates a new type of trail from AI-assisted hacking: the work itself in AI coding tools can leave behind context – name, age, location, targets and intent – that can be analyzed by cybersecurity companies. At the same time, CrowdStrike's cautious wording shows how difficult it is to move from such traces to a secure identity. President Lee Jae-myung's comment about signs of AI use in the hacking incidents shows that the case also carries political weight in South Korea, while it remains to be seen whether the technical findings will be followed up with legal steps.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.