BANK HACKS
CrowdStrike said the individual also asked Claude where threat actors typically sell Korean data breach information and sought assistance in finding Korean Telegram data sales groups.
In another session, the person also asked Claude to create a security researcher resume, which included details such as a Telegram account, age, educational background and a location in Maoming, a city in the southern Chinese province of Guangdong, which CrowdStrike said likely belonged to the attacker.
A man who answered a phone number provided by CrowdStrike in its report said he had no knowledge of the matter.
Anthropic, South Korean police and China’s foreign ministry did not immediately respond to requests for comment.
ARTEX is an open-source AI agent for automated penetration testing that was published on GitHub this year by a Chinese security engineer with the handle Autumn. It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude and DeepSeek to help organisations test for vulnerabilities in networks.
The tool’s GitHub page says it is intended for personal learning, code research and local technical verification and should not be used to conduct real-world testing against online systems or websites.
At least nine South Korean banks have disclosed or have been reported by local media as having been targeted by cyberattacks since late September, prompting South Korean police to launch a probe this week and President Lee Jae Myung to call for robust response measures.
Shinhan Bank said last week that the personal information of about 25,000 of its customers was compromised, while KB Kookmin Bank said that the personal information of 119 of its customers was leaked.

