A 26-year-old man in Guangdong, China, is suspected of using AI tools like ARTEX and Claude to target nine South Korean banks in recent cyberattacks.
Tags:A 26-year-old man believed to be based in Guangdong, China, has emerged as a possible suspect in a series of cyberattacks targeting South Korean banks, according to findings from US cybersecurity firm CrowdStrike.
The attacks, which reportedly began in late September and continued into early October, may have involved artificial intelligence tools designed to identify and exploit weaknesses in computer systems.
Citing a Reuters report published on October 8, CrowdStrike said its researchers uncovered clues about the potential attacker while examining AI-assisted programming sessions and digital infrastructure linked to the incidents.
Investigators identified the use of ARTEX, an open-source AI-powered penetration testing tool developed in China, alongside Claude Code, an AI coding assistant created by Anthropic.
CrowdStrike believes the individual may be a Chinese speaker with financial motivations. However, the company emphasized that these conclusions remain preliminary and that no suspect has been definitively identified.
AI Tools May Have Played a Role
According to the investigation, the suspected attacker used Claude to research online platforms where stolen South Korean personal information could potentially be sold.
The individual also reportedly sought assistance locating Telegram communities involved in trading Korean data.
Another significant clue emerged when researchers discovered a request for Claude to prepare a professional résumé for a cybersecurity researcher.
The resulting document reportedly included details suggesting the individual was 26 years old and based in Maoming, a city in China's Guangdong province. It also contained educational information and a Telegram contact.
While these details could offer clues about the person's identity, CrowdStrike cautioned that they have not been independently verified.
A person contacted through the telephone number mentioned in the report denied any knowledge of the alleged cyber activity.
Nine South Korean Banks Reportedly Targeted
At least nine banks in South Korea have reportedly experienced cyberattacks since late September, according to financial institution disclosures and local news reports.
Among the affected institutions, Shinhan Bank disclosed an incident involving the personal information of approximately 25,000 customers.
KB Kookmin Bank separately reported a data breach affecting 119 individuals.
South Korean law enforcement authorities have begun investigating the incidents to determine who was responsible and whether the attacks are connected.
What Is ARTEX?
ARTEX is an open-source cybersecurity tool that uses artificial intelligence to automate certain penetration-testing activities, including identifying potential security vulnerabilities.
It can integrate with AI systems such as ChatGPT, Claude and DeepSeek.
Its developers maintain that the software is intended for educational purposes, coding research and controlled security testing. They also warn against using it to target websites or computer systems without authorization.
Investigation Remains Open
CrowdStrike has not formally linked the cyberattacks to any established hacking group or confirmed the identity of the suspected individual.
The company assessed some of its findings with moderate confidence, citing Chinese-language instructions and the use of Chinese-developed software.
Anthropic, South Korean police and China's Ministry of Foreign Affairs had not publicly responded to requests for comment at the time of the original report.
The case highlights growing concerns about how AI-powered programming and security tools could potentially be misused in cybercrime, particularly when attacks involve sensitive financial and personal information.
For now, the alleged involvement of the 26-year-old Chinese man remains unconfirmed, and investigations into the bank breaches are continuing.
No comments:
Post a Comment