CrowdStrike Links Cyberattacks on South Korean Banks to a Suspect in China Using AI Tools
October 11, 2026 · 3 min read
CrowdStrike reported on October 7 that a series of cyberattacks targeting financial institutions in South Korea appears to have been conducted by an individual residing in China who utilized artificial intelligence tools. The security firm analyzed servers associated with the attacks and found evidence suggesting the perpetrator used an open-source intrusion testing tool developed in China alongside multiple large language models. While CrowdStrike has not definitively identified the attacker, the analysis uncovered personal information that points to a twenty-six-year-old male living in Maoming City, Guangdong Province, although this identification remains unconfirmed.
The wave of information leaks affecting South Korean banks began in late September. According to reports, at least nine banks have been confirmed as targets of these breaches. CrowdStrike discovered the relevant servers through an exposed directory linked to specific internet protocol addresses used in the campaign. Within these servers, investigators found configuration files for the automated testing tool known as ARTEX and usage logs from an artificial intelligence coding assistant called Claude Code. These records indicated that the attacker focused on the same financial entities that later reported data losses, with activity spanning from late September into early October.
The primary software weapon in this campaign was ARTEX, an intrusion test automation tool released on GitHub in 2026 by a security engineer in China. The tool is designed to work with external large language models to identify system vulnerabilities, allowing users to select which models to connect. In this specific instance, the attacker primarily leveraged a model named DeepSeek v4.1-flash from the Chinese company DeepSeek. The logs also showed connections to other models, including GLM-5.3 from Zhipu AI in China and Grok 4.6 from xAI in the United States. The tool's public documentation restricts its use to personal learning and code research, explicitly forbidding its application against live systems or websites.
CrowdStrike determined that the operation relied on two distinct servers. One server, based in Hong Kong, served as the central infrastructure for the attacks, while the second server ran the ARTEX software. On the server hosting the automation tool, investigators found documents written in Chinese that provided instructions to the connected language models on how to proceed with the intrusion tests. The attacker further obscured their trail by routing activities through nine different proxy internet protocol addresses. This setup allowed for a coordinated effort to probe and exploit weaknesses in the targeted banking networks.
The motivation behind the attacks appears to be financial gain, a conclusion CrowdStrike reached with moderate confidence based on the use of Chinese-language tools and instructions. The usage logs from the AI coding assistant revealed queries about marketplaces for selling leaked data from South Korea and methods for locating South Korean groups on the messaging platform Telegram dedicated to data sales. Additionally, the logs showed requests for the artificial intelligence to draft a resume for a security researcher, incorporating the recent attacks as professional achievements. In these requests, the user claimed to be twenty-six years old and provided a Telegram username and educational history.
Despite the detailed digital footprint, CrowdStrike stops short of confirming the identity of the suspect. When journalists attempted to contact the phone number listed in the discovered documents, the man who answered denied any knowledge of the incident. Adam Meyers, who oversees threat tracking at CrowdStrike, described the event as a clear example of a human attacker leveraging artificial intelligence agents to execute widespread attacks. He noted that the integration of these tools enables a single individual to target a large number of victims over a very short period, marking a shift in the scale of potential threats posed by lone actors.