Business

Chinese-based suspect linked to South Korean bank hacks via AI tools

A 26-year-old individual in China’s Guangdong province is suspected of orchestrating cyberattacks against at least nine South Korean banks since late September. CrowdStrike investigators identified the attacker after discovering personal details inadvertently leaked during sessions using Anthropic’s Claude Code and a Chinese-developed AI penetration tool named ARTEX.

Chinese-based suspect linked to South Korean bank hacks via AI tools

The investigation revealed that the suspect utilized ARTEX, an open-source tool designed for automated security testing, to probe financial networks. While the tool’s creator intended it for local research, its integration with large language models enabled the attacker to streamline malicious activity. CrowdStrike analysts tracked the sessions, noting that the individual frequently used Chinese-language prompts and sought advice on selling stolen Korean data through Telegram channels.

In a lapse of operational security, the suspect prompted Claude to draft a resume containing specific personal information, including an age, educational background, and a location in Maoming. When reached at a number associated with these sessions, a man denied any involvement. The breach has triggered a wider investigation by South Korean police following high-profile data leaks at institutions like Shinhan Bank and KB Kookmin Bank. This incident highlights growing concerns over the weaponization of autonomous AI agents, echoing recent warnings from Australian officials regarding similar breaches in government systems.

Comments

Comments (0)

Leave a comment

No comments yet. Be the first!