A Chinese-speaking hacker used the ARTEX AI agentic penetration testing suite alongside Claude Code agents to breach multiple South Korean banks earlier this month, according to security firm CrowdStrike. The attacks hit major institutions including Shinhan Bank, KB Kookmin Bank, and Hana Bank, exposing customers’ personal data and credit card information and causing outages at some of the targeted banks.

The breaches prompted an emergency meeting by the South Korean government, which called for immediate security upgrades across critical financial IT systems.

How researchers tied the attack together

CrowdStrike identified the attacker’s infrastructure and found open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files. According to the researchers, the ARTEX instance ran on DeepSeek v4.1-flash as its primary language model backend, with the attacker supplementing it using GLM-5.3 from Zhipu AI and Grok 4.6 for additional Claude Code sessions. The threat actor appears to have accessed DeepSeek through a likely LLM API proxy or reseller identified as xcai[.]pro.

The exposed session data also revealed the attacker’s targets, which overlapped with institutions named in prior financial-sector breach reporting, giving CrowdStrike high confidence in the attribution.

The attacker exposed their own identity

In an ironic twist, the threat actor used the same AI tools to generate a résumé, which leaked identification details, contact information, and a Telegram handle. Based on that résumé, CrowdStrike assesses the attacker may be a 26-year-old individual who studied at South China University of Technology and resides in Maoming, Guangdong, China. However, the attacker initially listed a birth year of 2007, undermining confidence in the personal details. CrowdStrike cautions that while the information may belong to the person behind the ARTEX activity, it is not reliable enough to confirm identity.

Records also show the attacker had no concrete plan to monetize the stolen banking data and had asked Claude to suggest Telegram groups focused on selling Korean data.

ARTEX goes closed-source, but derivatives remain

After confirming ARTEX had been used in real-world attacks, its developer made the project closed-source and halted further updates. Despite that move, the existing codebase has already spawned English- and Korean-language derivatives, meaning the tool in its current form remains available to other threat actors.