Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report报道称,一名讲中文的黑客可能与针对韩国银行的AI驱动攻击有关。
SEOUL, Oct. 8 (Yonhap) -- U.S. cybersecurity firm CrowdStrike said an unidentifi...

This will let Google show Yonhap news articles that match or are related to your search
SEOUL, Oct. 8 (Yonhap) -- U.S. cybersecurity firm CrowdStrike said an unidentified hacker believed to be a Chinese speaker used artificial intelligence (AI)-powered hacking tools to breach multiple South Korean financial institutions and steal data.
In a report released Wednesday (U.S. time), CrowdStrike said the attacker used ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models (LLMs) to carry out cyberattacks between late September and early October.
The findings come amid a series of data breaches at South Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank, prompting financial authorities and investigators to launch probes into the incidents.
A pedestrian passes by a KB Kookmin Bank in Seoul on Oct. 2, 2026. (Yonhap)
According to CrowdStrike, the compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees.
"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in the report.
"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts."
The cybersecurity firm said the attacker primarily used DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6 through Claude Code sessions.
In one Claude Code session, the attacker asked Claude to draft a security researcher resume using personal details, including an age of 26 and an educational background at South China University of Technology in Guangdong, China.
However, the attacker's identity, the full extent of the breaches and the amount of stolen data remain unconfirmed.
CrowdStrike also identified two servers used in the attacks: one based in Hong Kong serving as the attacker's primary infrastructure and another hosting ARTEX, which was likely used to target South Korean financial institutions.
An analysis of files showed the attacker asked Claude about marketplaces for stolen South Korean data and Telegram groups involved in selling such information, suggesting a possible financial motive.
ejkim@yna.co.kr (END)
Multiple IPs used to hide origin of recent cyberattacks against financial firms
(LEAD) 28 IP addresses behind recent hacking attacks against Korean financial institutions: watchdog
(LEAD) Lee calls for thorough probe into personal data leaks at financial institutions
Financial watchdog calls emergency meeting with heads of financial firms under hacking attacks
(2nd LD) Regulator instructs financial firms to check security systems over series of cyberattacks on banks
Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report
这将使谷歌能够向您展示与您的搜索匹配或相关的韩联社新闻文章
首尔,10 月 8 日(韩联社)——美国网络安全公司 CrowdStrike 表示,一名身份不明的黑客(据信会说中文)使用人工智能 (AI) 驱动的黑客工具入侵了多家韩国金融机构并窃取了数据。
CrowdStrike 在周三(美国时间)发布的一份报告中称,攻击者使用了中国开发的开源人工智能渗透测试工具 ARTEX 以及大型语言模型 (LLM),在 9 月下旬至 10 月初期间实施了网络攻击。
调查结果出炉之际,韩国多家金融机构,包括韩亚银行、KB国民银行和新韩银行,相继发生数据泄露事件,促使金融监管机构和调查人员对这些事件展开调查。
2026年10月2日,一名行人走过首尔的KB国民银行。(韩联社)
据 CrowdStrike 称,被入侵的系统包括一家银行供金融经纪人使用的贷款查询服务,以及另一家银行供员工使用的移动工作支持系统。
CrowdStrike 在报告中表示:“虽然尚未确定此次攻击活动是由哪个特定对手发起的,但攻击者很可能是讲中文的人,并且有经济动机。”
“本次评估基于使用中国开发的工具ARTEX和观察到的中文提示语,置信度中等。”
网络安全公司表示,攻击者主要使用 DeepSeek v4.1-flash,并通过 Claude Code 会话辅以 GLM-5.3 和 Grok 4.6。
在一次 Claude Code 会话中,攻击者要求 Claude 使用个人信息(包括 26 岁的年龄和在中国广东华南理工大学的教育背景)起草一份安全研究员简历。
然而,攻击者的身份、入侵的全部范围以及被盗数据的数量仍未得到证实。
CrowdStrike 还确定了攻击中使用的两个服务器:一个位于香港,作为攻击者的主要基础设施;另一个托管 ARTEX,该服务器可能用于攻击韩国金融机构。
文件分析显示,攻击者曾向克劳德询问有关被盗韩国数据的交易市场以及参与出售此类信息的 Telegram 群组,这表明攻击者可能存在经济动机。
ejkim@yna.co.kr (完)
多个IP地址被用来隐藏近期针对金融公司的网络攻击的来源。
(导语)监管机构称,近期针对韩国金融机构的黑客攻击背后有28个IP地址
(导语)李呼吁对金融机构的个人数据泄露事件进行彻底调查
金融监管机构召集遭受黑客攻击的金融机构负责人召开紧急会议
(第二条)监管机构指示金融公司检查安全系统,以应对一系列针对银行的网络攻击。
报道称,一名讲中文的黑客可能与针对韩国银行的AI驱动攻击有关。