Back to Feed
Nation-stateOct 10, 2026

ARTEX AI, Claude agents used in cyberattacks on South Korean banks

Chinese hacker uses ARTEX AI and Claude agents to attack South Korean banks.

Summary

A Chinese-speaking hacker targeted multiple South Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank, using the ARTEX AI penetration testing suite and Claude agents. The attacks resulted in the exposure of client data and credit card information, and caused system outages. CrowdStrike confirmed the use of ARTEX AI and identified the attacker's infrastructure, which included Claude Code session histories and memory files.

Full text

ARTEX AI, Claude agents used in cyberattacks on South Korean banks By Bill Toulas October 10, 2026 10:16 AM 0 A Chinese-speaking hacker launched cyberattacks that shook the South Korean financial sector earlier this month, using the ARTEX AI penetration testing suite and Claude agents. The actor targeted multiple Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank, exposing clients ' personal data and credit card information, and causing system outages in some cases. The South Korean government reacted with an emergency meeting and calls for immediate security measures for critical IT systems. Security firm CrowdStrike confirmed the use of ARTEX AI, up until recently an open-source agentic penetration testing suite developed in China. Researchers identified the attacker's infrastructure and found open directories with Claude Code session histories, ARTEX configuration files, and Claude memory files. “The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions,” CrowdStrike explained. “The threat actor likely accessed DeepSeek via the likely LLM API proxy/reseller xcai[.]pro,” the researchers noted. These records also provided insight into the attacker’s activities, with targets overlapping those named in previous reporting about financial-sector breaches, allowing for high-confidence linking. Because the threat actor used the same AI tools to create a résumé, they also exposed identification, contact, and Telegram account details. Based on information in the résumé, CrowdStrike says that the attacker may be a 26-year-old Chinese who studied at the South China University of Technology and lives in Maoming, Guangdong, China. However, the researchers found that the attacker initially provided a date of birth in 2007. Although the personal details may belong to the individual behind the ARTEX-related activity, they are not reliable enough to confirm the threat actor’s identity. The records show the attacker had no specific plan to monetize the data stolen from South Korean banks, and asked Claude to propose Telegram data-sales groups focused on Korea. After confirming that ARTEX had been used in real-world attacks, the developer decided to make the project closed-source and discontinue further updates. However, the project’s current code has been used to create English- and Korean-language derivatives, so it’s still available in its current form. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Anthropic asks Claude users to share voice data for AI model trainingAnthropic turns Claude into an AI marketplace with 2,000+ plugins and connectorsClaude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longerAnthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessionsAnthropic wants Claude to analyze your bank account and financial data

Indicators of Compromise

  • domain — xcai.pro

Entities

ARTEX AI (product)Claude agents (product)Claude Code (product)DeepSeek v4.1-flash (product)GLM-5.3 (product)Grok 4.6 (product)