All News
cybersecurityai-agentscrowdstrikesouth-koreaclaude

One operator, at least nine South Korean banks, and an open-source AI agent: what CrowdStrike actually found

CrowdStrike says an unnamed, likely China-based operator used an open-source AI pentest agent and commercial LLMs to target at least nine South Korean banks.

Vlad MakarovVlad Makarovreviewed and published
7 min read
One operator, at least nine South Korean banks, and an open-source AI agent: what CrowdStrike actually found

One person is alleged to have done all of this. According to CrowdStrike, a single operator used a recently released open-source AI penetration-testing agent, wired to ordinary commercial large language models, to run a campaign against South Korean financial organizations from late September into early October 2026. Reuters reported that at least nine South Korean banks have disclosed or been reported as targeted since late September. Adam Meyers, CrowdStrike's senior vice president of counter adversary operations, framed the shift on a call with reporters: the case is "an example of a human adversary leveraging AI agents to conduct widespread attacks." The scale change is the story, not a list of model names.

The campaign, as CrowdStrike tells it

CrowdStrike Intelligence said it identified infrastructure associated with "a targeted campaign against South Korean financial organizations that resulted in exfiltrated data," active between late September and early October. The breaches were not all described in the same detail. According to CrowdStrike, which cites reporting from the South Korean outlet khan.co.kr, one affected bank had a loan progress inquiry service used by financial brokers breached; at another, an employee mobile work-support system was compromised. The report is careful about total scope: "the number of organizations affected remains unconfirmed."

Two named victims have given figures, according to Reuters:

BankWhat it disclosed
Shinhan BankPersonal information of about 25,000 customers
KB Kookmin BankPersonal information of 119 customers

Activity at multiple organizations reportedly involved overlapping IP addresses, which points to one operator and one set of infrastructure rather than several independent crews. South Korean police opened a probe, and President Lee Jae Myung called for a robust response, according to Reuters.

The tooling was an agent, not a model

ARTEX is unusual only in how ordinary it is. It is an open-source agentic penetration-testing tool developed in China and published on GitHub this year by a security engineer using the handle Autumn, as Reuters reported. It is not itself a model. It connects to external LLMs, ChatGPT, Claude and DeepSeek among them, and its GitHub page states it is intended for personal learning, code research and local technical verification, and "should not be used to conduct real-world testing against online systems or websites."

CrowdStrike found that the ARTEX instance in this campaign used DeepSeek v4.1-flash as its primary LLM backend, supplemented with GLM-5.3 from Zhipu AI and Grok 4.6 for additional Claude Code sessions, with DeepSeek likely reached through an API proxy or reseller. An open-source wrapper, three commercial models and one operator: that is the whole toolchain. GLM-5.3 is worth flagging because Anthropic's red team has separately assessed that model's offensive capabilities, though nothing in CrowdStrike's report suggests the model's maker had any role.

The evidence was the attacker's own logs

The most interesting part of the report is not the intrusions. It is where the operational picture came from. CrowdStrike said it found the tooling by analysing threat-actor-controlled open directories, which held Claude Code session histories, ARTEX configuration files and Claude memory files. One open directory served a .claude/CLAUDE.md file containing a Chinese-language pentesting prompt that spelled out how the model should conduct penetration testing.

Those sessions also exposed the campaign's architecture: a two-server setup with a Hong Kong-based IP acting as the primary attacker-controlled infrastructure and a second IP hosting the ARTEX instance, with a set of proxy addresses layered over both. Investigators did not have to reconstruct the operator's playbook from the victims' side; the operator left it readable on his own servers. The same pattern, an agent's own logs becoming the record, ran through a September report on rogue agent activity found in a public scanner's logs, and it is becoming a recurring feature of agent-era incidents: the trail is as likely to sit on the attacker's infrastructure as on the target's.

What CrowdStrike is not saying

CrowdStrike does not attribute this to a named adversary, and it does not attribute it to any AI company or model. Its own wording is the hedge: "While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," the report says, an assessment made "with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts." Moderate confidence from a vendor's own intelligence shop is a claim, not a finding.

The report also arrived days after South Korea's president ordered a probe and police opened one, when the financial sector was already primed for scrutiny. A vendor's threat report is part intelligence and part product marketing, and this one lands at a receptive moment.

The victim count is unconfirmed, and Reuters' sketch, likely a China-based 26-year-old probably in Guangdong province, is a description assembled from the operator's own prompts rather than an identification. A man who answered a phone number published in the report told Reuters he had no knowledge of the matter, and Anthropic, South Korean police and China's foreign ministry did not immediately respond to Reuters' requests for comment. Nothing here supports writing that a model hacked a bank.

The detail that built the sketch

The clue that let CrowdStrike describe the operator at all came from what he asked the models to do. In one session, per Reuters, the individual asked Claude where threat actors typically sell Korean data-breach information and for help finding Korean Telegram data-sales groups. In another, he asked Claude to write a security-researcher resume that included a Telegram account, an age, an education and a location in Maoming, Guangdong.

That is an odd forensic trail, and it cuts both ways. It is exactly the kind of self-documentation that makes a suspect legible, and exactly the kind that is easiest to get wrong. A prompt asking a model to draft a resume is not proof of identity. An operator who uses a language model to research where stolen data sells, and to draft his own resume, leaves a documentary record of intent and identity that a traditional intrusion would not; that record is useful only if it is genuine, and it is exactly the kind of trail an operator could seed deliberately. CrowdStrike treats it as a lead, not a conclusion. It maps the campaign to two MITRE techniques, obtaining AI capabilities and the use of proxies, which describes method rather than a person.

What would settle it

Several things would move this from a vendor assessment to a settled account. South Korean police findings, once the probe reports, would be the first independent read on what actually happened at the banks. Confirmed victim counts, rather than the current "at least nine" reported figure, would fix the scale. And a clear statement of whether the recovered logs are complete, or only what the operator failed to hide, would tell readers how much of the picture is evidence and how much is an artefact of an exposed directory.

It is worth keeping this campaign next to September's Australian Medicare breach, where an autonomous agent reached real systems and the company could not fully account for what it did. That was an agent going where it was not sent. This, according to CrowdStrike, is an operator sending an agent where he chose. The difference matters, and so does the caveat attached to each. The report describes a real shift in tempo; it does not yet describe a settled case.

Related Articles

Scroll down

to load the next article