News with an accent.

A multi-story office tower with the Shinhan Bank name and logo near the top, among other Seoul high-rises.
Sede de Shinhan Bank en Seúl, en una imagen de archivo.Mobius6 / Wikimedia Commons, CC BY-SA 4.0. Imagen de archivo
Privacy

CrowdStrike finds ARTEX AI and Claude Code in attacks on banks

The security firm assesses with moderate confidence that a Chinese-speaking attacker used AI agents; the banks have not confirmed the tool.

Security firm CrowdStrike found traces of ARTEX AI and Claude Code sessions on servers used by the attacker who hit South Korean banks. It published the findings on Oct. 7. ARTEX AI is an open-source tool of Chinese origin that puts artificial intelligence agents to work on penetration testing, meaning simulated attacks used to find weaknesses.

In open directories on one server, analysts saw the history of the Claude Code sessions, the ARTEX configuration and Claude memory files. According to BleepingComputer, the attacker also asked Claude to suggest Telegram groups where stolen Korean data is sold. The report does not say which provider served those sessions, and BleepingComputer's story includes no response from Anthropic.

CrowdStrike does not tie the campaign to a named group. It says, with "moderate confidence," that the actor probably speaks Chinese and is financially motivated. The ARTEX instance used DeepSeek v4.1-flash as its main model.

The banks' own reports, according to Korea JoongAng Daily, are narrower:

Data leaks reported by South Korean banks since Oct. 1
InstitutionData exposed
Shinhan BankMore than 25 000 customers
KB Kookmin Bank119 customers
Hana Bank89 customers
BNK Financial Group11 cases
Source: Korea JoongAng Daily

Woori Bank and NH Nonghyup Bank faced similar attacks but reported no data leaks. At Shinhan, the access was to a service used only by loan brokers.

The authorities respond

On Oct. 2, South Korea's Financial Services Commission called an emergency meeting and ordered a security review across the sector. It asked institutions to list IT assets reachable from the internet, including AI systems, and to check for paths that give access to internal information without authentication. Its secretary general, Shin Jin-chang, said institutions must be "fully prepared" to limit harm to consumers after an incident.

Several points remain unconfirmed. Neither any bank nor the commission has said publicly that ARTEX was behind every intrusion. That link comes from CrowdStrike and press reports. CrowdStrike also does not specify what data was taken or how many organizations were affected. BleepingComputer adds that ARTEX's author decided to close the source code and stop releasing versions, but derivative copies in English and Korean already exist.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)