Trusence Every claim has a source
Last updated 10 October 2026 Search Türkçe
← All stories
Security

CrowdStrike links ARTEX AI and Claude agents to bank intrusions in South Korea

The attacks exposed customer data and disrupted some bank services, raising the cost of a campaign tied to AI tooling.

CrowdStrike says a Chinese-speaking attacker used ARTEX AI and Claude agents in intrusions against several South Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank, which led to exposed customer data and some outages. The firm found session logs, configuration files, and memory files on the attacker’s infrastructure, tying the campaign to DeepSeek v4.1-flash with additional use of GLM-5.3 and Grok 4.6 through Claude Code sessions. CrowdStrike also says the attacker likely accessed DeepSeek through an API proxy at xcai[.]pro and used the same tools to generate a résumé that exposed contact details and Telegram information. After the activity came to light, ARTEX’s developer said the project would be closed-source and stop receiving updates, although derivatives in English and Korean already exist.

Why it matters

The reported intrusions show AI-assisted tooling being used in real attacks against named banks, with customer data exposed and some outages reported. That matters for the institutions involved because the impact went beyond access attempts and reached customer-facing harm. It also prompted ARTEX’s developer to end updates and move the project closed-source after the tool was confirmed in live attacks.

Sources

  • BleepingComputer