Latest update
A hacker behind attacks on Korean banks asked Claude Code where to sell stolen data, CrowdStrike found
First seen on X 19 hours ago@AndrewCurran_ ♥ 37029 views
In a report published October 7 (US time), CrowdStrike said an actor who stole data from South Korean financial organizations between late September and early October used ARTEX, an open-source agentic pentesting tool built in China. DeepSeek v4.1-flash was the main model behind it, with GLM-5.3 and Grok 4.6 added in Claude Code sessions. The actor's Claude Code session histories and memory files sat in open directories on the actor's own servers.
Those logs include questions about where Korean breach data is usually sold and requests to find Korean Telegram groups that trade it. CrowdStrike assesses with moderate confidence that the actor is a financially motivated Chinese speaker, and says the number of affected organizations is still unconfirmed. According to Reuters, at least nine South Korean banks have been reported as targets since late September; Shinhan Bank said about 25,000 customers' data was compromised and KB Kookmin Bank said 119. The report says AI tooling lets one actor run multiple intrusions in a short time.