Chinese-speaking hacker possibly linked to AI-driven attacks on S. Korean banks: report报道称,一名讲中文的黑客可能与针对韩国银行的AI驱动攻击有关。
U.S. cybersecurity firm CrowdStrike said an unidentified hacker believed to be a Chinese speaker used artificial intelligence (AI)-powered hacking...

A Chinese-speaking hacker used AI-powered tools to breach multiple Korean financial institutions between late September and early October, CrowdStrike said in a report released Wednesday. The attacker used the China-developed ARTEX penetration-testing tool and large language models, while the breaches prompted investigations by financial authorities. The hacker’s identity, the full scope of the intrusions and the amount of stolen data remain unconfirmed.
CrowdStrike said the compromised systems included a bank’s loan inquiry service for financial brokers and another bank’s mobile work-support system for employees.
The attacker primarily used DeepSeek v4.1-flash and supplemented it with GLM-5.3 and Grok 4.6 through Claude Code sessions.
CrowdStrike identified a Hong Kong server as the attacker’s primary infrastructure and another server hosting ARTEX that was likely used to target Korean financial institutions.
Files showed the attacker asked Claude about marketplaces for stolen Korean data and Telegram groups involved in selling such information.
In one Claude Code session, the attacker requested a security researcher resume using personal details including an age of 26 and education at South China University of Technology in Guangdong, China.
Published Oct 8, 2026 10:03 am KST
A pedestrian passes by a KB Kookmin Bank in Seoul, Oct. 2. Yonhap
U.S. cybersecurity firm CrowdStrike said an unidentified hacker believed to be a Chinese speaker used artificial intelligence (AI)-powered hacking tools to breach multiple Korean financial institutions and steal data.
In a report released Wednesday (U.S. time), CrowdStrike said the attacker used ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models (LLMs) to carry out cyberattacks between late September and early October.
The findings come amid a series of data breaches at Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank, prompting financial authorities and investigators to launch probes into the incidents.
According to CrowdStrike, the compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees.
"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in the report.
"This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts."
The cybersecurity firm said the attacker primarily used DeepSeek v4.1-flash, supplemented by GLM-5.3 and Grok 4.6 through Claude Code sessions.
In one Claude Code session, the attacker asked Claude to draft a security researcher resume using personal details, including an age of 26 and an educational background at South China University of Technology in Guangdong, China.
However, the attacker's identity, the full extent of the breaches and the amount of stolen data remain unconfirmed.
CrowdStrike also identified two servers used in the attacks: one based in Hong Kong serving as the attacker's primary infrastructure and another hosting ARTEX, which was likely used to target Korean financial institutions.
An analysis of files showed the attacker asked Claude about marketplaces for stolen Korean data and Telegram groups involved in selling such information, suggesting a possible financial motive.
CrowdStrike周三发布的一份报告称,一名讲中文的黑客利用人工智能工具,于9月下旬至10月初期间入侵了多家韩国金融机构。攻击者使用了中国开发的ARTEX渗透测试工具和大型语言模型,此次入侵事件引发了金融监管机构的调查。目前,黑客的身份、入侵范围以及被盗数据量均尚未得到证实。
CrowdStrike 表示,被入侵的系统包括一家银行面向金融经纪人的贷款查询服务系统和另一家银行面向员工的移动工作支持系统。
攻击者主要使用 DeepSeek v4.1-flash,并通过 Claude Code 会话补充了 GLM-5.3 和 Grok 4.6。
CrowdStrike 发现攻击者的主要基础设施是一台香港服务器,另一台托管 ARTEX 的服务器可能被用来攻击韩国金融机构。
文件显示,攻击者曾向克劳德询问有关被盗韩国数据的交易平台以及参与出售此类信息的 Telegram 群组的信息。
在一次 Claude Code 会话中,攻击者请求提供安全研究人员的简历,简历中包含 26 岁和在中国广东华南理工大学接受教育等个人信息。
发布于2026年10月8日上午10:03(韩国标准时间)
10月2日,一名行人走过首尔的KB国民银行。(韩联社)
美国网络安全公司 CrowdStrike 表示,一名身份不明的黑客(据信是讲中文的人)使用人工智能 (AI) 驱动的黑客工具入侵了多家韩国金融机构并窃取了数据。
CrowdStrike 在周三(美国时间)发布的一份报告中称,攻击者使用了中国开发的开源人工智能渗透测试工具 ARTEX 以及大型语言模型 (LLM),在 9 月下旬至 10 月初期间实施了网络攻击。
此前,包括韩亚银行、KB国民银行和新韩银行在内的多家韩国金融机构发生数据泄露事件,促使金融监管机构和调查人员对这些事件展开调查。
据 CrowdStrike 称,被入侵的系统包括一家银行供金融经纪人使用的贷款查询服务,以及另一家银行供员工使用的移动工作支持系统。
CrowdStrike 在报告中表示:“虽然尚未确定此次攻击活动是由哪个特定对手发起的,但攻击者很可能是讲中文的人,并且有经济动机。”
“本次评估基于使用中国开发的工具ARTEX和观察到的中文提示语,置信度中等。”
网络安全公司表示,攻击者主要使用 DeepSeek v4.1-flash,并通过 Claude Code 会话辅以 GLM-5.3 和 Grok 4.6。
在一次 Claude Code 会话中,攻击者要求 Claude 使用个人信息(包括 26 岁的年龄和在中国广东华南理工大学的教育背景)起草一份安全研究员简历。
然而,攻击者的身份、入侵的全部范围以及被盗数据的数量仍未得到证实。
CrowdStrike 还确定了攻击中使用的两个服务器:一个位于香港,作为攻击者的主要基础设施;另一个托管 ARTEX,该服务器可能用于攻击韩国金融机构。
文件分析显示,攻击者曾向克劳德询问有关被盗韩国数据的交易市场以及参与出售此类信息的 Telegram 群组,这表明攻击者可能存在经济动机。