According to U.S. cybersecurity company CrowdStrike, a 26-year-old person living in China’s Guangdong province could be responsible for a wave of cyberattacks directed at South Korea’s banking industry.
Between late September and early October, the suspected perpetrator reportedly leveraged Anthropic’s Claude Code and ARTEX, a Chinese-built AI agent, to launch operations against South Korean financial institutions.
CrowdStrike Identifies Suspected Attacker
In a Wednesday report, CrowdStrike stated that it uncovered identifying personal details tied to the potential attacker by examining infrastructure and AI coding-tool sessions connected to the campaign.
Although the cybersecurity company has not assigned the activity to a specific named adversary, it holds moderate confidence that the threat actor is a Chinese speaker driven by financial motives. This conclusion stems from the implementation of the Chinese-made ARTEX tool alongside observed prompts written in Chinese.
CrowdStrike revealed that the suspect also queried Claude regarding where threat actors generally market Korean data breaches and requested assistance in locating Korean data-sales groups on Telegram.
During another session, the individual instructed Claude to draft a security researcher resume incorporating specific details such as a Telegram handle, age, academic history, and a base in Maoming, a municipality within Guangdong province. CrowdStrike indicated these particulars likely pertain to the attacker.
Also Read: ‘ASOS HACKED’: Shoppers Receive Threatening App Message Over Snowflake Data
AI Agent Used in Bank Attacks
Designed for automated penetration testing, ARTEX functions as an open-source AI agent. A Chinese security engineer operating under the alias Autumn released the software on GitHub earlier this year.
Rather than acting as an independent large language model, the utility integrates with external models like DeepSeek, ChatGPT, and Claude to assist entities in checking network vulnerabilities. Its GitHub repository specifies that the software is meant strictly for personal education, code research, and local technical testing, advising against its deployment for real-world offensive operations against online systems or websites.
Local media reports and official disclosures indicate that at least nine South Korean banks have faced cyberattacks since late September. These incidents led South Korean law enforcement to open an investigation this week, with President Lee Jae Myung urging a decisive response.
Shinhan Bank reported that the private data of roughly 25,000 customers was breached, whereas KB Kookmin Bank stated that information belonging to 119 customers was leaked.
Requests for comment sent to Anthropic, the Chinese foreign ministry, and South Korean police were not answered immediately.




