Start your day with intelligence. Get The OODA Daily Pulse.

Home > Briefs > Cyber > Analysis of Chinese hacker’s AI powered cyber attack against South Korean banks

Analysis of Chinese hacker’s AI powered cyber attack against South Korean banks

CrowdStrike reported on October 7 that a financially motivated actor, probably Chinese-speaking, breached South Korean banks between late September and early October 2026 and took data. CrowdStrike hasn’t tied the actor to any named group. The main tool was ARTEX, an open-source AI penetration-testing tool built in China. The actor ran it mostly on DeepSeek and also used GLM, Grok and Claude Code sessions. At one bank the actor reportedly got into a loan-inquiry service that brokers use. At the second it compromised an employee mobile work-support system. How many organizations were hit in total isn’t confirmed. Analysts found the operation through exposed open directories on the attacker’s servers. They held Claude Code session histories, ARTEX configs and Chinese-language prompts, and one prompt asked where Korean breach data gets sold, including on Telegram. CrowdStrike’s main point is that AI tooling let one person run several intrusions quickly. The report gives IOCs and ATT&CK mappings but doesn’t say how the actor first got in.

Full analysis : Chinese speaking hacker targeted South Korean banks using LLMs and open-source Chinese agentic tool ARTEX.