Chinese Hacker Unleashes ARTEX AI and Claude Agents on South Korean Banks

Chinese Hacker Unleashes ARTEX AI and Claude Agents on South Korean Banks

A hacker fluent in Chinese has shaken up the South Korean banking scene this month, wielding the ARTEX AI penetration testing suite and Claude agents like a toddler with a brand-new toy.

This cyber-sorcerer didn’t discriminate, setting sights on major players like Shinhan Bank, KB Kookmin Bank, and Hana Bank. Naturally, personal data and credit card info are now public knowledge, and some systems experienced outages—because who doesn’t enjoy a little chaos with their banking?

In a masterclass of reactive governance, South Korea's government rushed into action with an emergency meeting and a call for immediate security measures. Because waiting until after the storm hits is clearly the best strategy.

According to CrowdStrike, the magical ARTEX AI, once a friendly open-source penetration testing suite from China, was at the center of this mess. Researchers traced the hacker’s digital footprints and stumbled upon open directories filled with the criminal’s session histories, ARTEX configuration files, and Claude memory files. Clearly, they were just one step away from posting their plans on social media.

The attack reportedly utilized DeepSeek v4.1-flash as the main LLM backend, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6. This hacker was not just throwing darts but had a full-blown arsenal of AI tools at their disposal. Apparently, they accessed DeepSeek via a likely API proxy/reseller called xcai[.]pro. The hacker’s creativity is certainly impressive.

CrowdStrike also revealed that the hacker is likely a 26-year-old from Guangdong, China, who enjoyed a brief stint at the South China University of Technology. However, our cybersecurity sleuths found discrepancies, including a suspiciously youthful date of birth in 2007 on the résumé, casting doubt on the authenticity of this genius's background.

The hacker's grand plan didn’t even include monetization of the stolen data. They were more interested in letting Claude suggest Telegram data-sales groups focused on Korea while exposing their own identity with reckless abandon.

In response to the chaos unleashed, the ARTEX developers decided to pack it up and turn the project closed-source, as if that would magically erase the havoc already wrought. Meanwhile, the existing code’s still floating around, giving the whole world a front-row seat to the future of cybercrime.

And so, the saga continues as banks scramble to implement new security measures, likely while contemplating how they’re going to explain all this to their clients.

Read More

Got Something To Say?

Your email address will not be published.