CrowdStrike: Korean bank hacker used Claude Code and DeepSeek — and left the AI logs on an open server
In a report published on October 7, 2026 (US time), CrowdStrike said the attacker behind the late-September and early-October breaches of South Korean banks and savings banks likely combined ARTEX, an open-source AI penetration-testing tool built in China, with Anthropic's AI coding agent Claude Code. ARTEX ran mainly on DeepSeek v4.1-flash, with Zhipu AI's GLM-5.3 and xAI's Grok 4.6 also in use. The evidence came from the attacker's own infrastructure: an exposed directory held Claude Code conversation logs, ARTEX configuration files and AI memory files. CrowdStrike did not name a group and assessed with moderate confidence that the operator is a Chinese-speaking individual motivated by money
The three lines
- Evidence — Claude Code session logs, ARTEX configs and AI memory files found in the attacker's open folders
- Toolkit — ARTEX on DeepSeek v4.1-flash for intrusion, GLM-5.3 and Grok 4.6 as helpers; Hong Kong server as hub
- Identity — a resume request left a name, university and Guangdong hometown; CrowdStrike will not confirm it
Key questions
- CrowdStrike South Korea bank hack report
- **Published October 7, 2026 (US time). It concludes several AI tools were chained together against Korean financial firms.** | Item | Detail | |---|---| | Attack window | Late September to early October 2026 | | Targets | South Korean banks, savings banks and other lenders | | Intrusion tool | ARTEX, a Chinese open-source AI pentest agent | | AI models | DeepSeek v4.1-flash (main), GLM-5.3, Grok 4.6, Claude Code sessions | | Infrastructure | Hong Kong server, a separate ARTEX server, 9 proxy IPs | | Assessment | Chinese-speaking, financially motivated — moderate confidence |
- Was Claude hacked in the Korean bank attack
- **No. The attacker ran Claude Code as a tool; Anthropic's systems were not breached.** | Point | Detail | |---|---| | Claude Code's role | AI coding agent run by the attacker on their own server | | What was left | Session logs and memory files | | Requests seen | Where stolen Korean data is sold; how to find Telegram data-selling groups | | Other models | Some sessions also used GLM-5.3 and Grok 4.6 |
- What is ARTEX hacking tool
- **An autonomous AI penetration-testing agent. Its developer closed the source after the report.** | Item | Detail | |---|---| | What it does | AI agents find and exploit weaknesses without step-by-step human input | | Developer | Chinese developer, GitHub account Autumn-27 | | Response | Repository made private, public releases stopped | | Limit | Copies already downloaded under an open licence keep working |
The attacker did not cover their tracks. They left their own server folders open to the internet, complete with their conversations with AI. In a report released on October 7, 2026 (US time), CrowdStrike's threat intelligence unit dissected the wave of breaches that hit South Korean banks and savings banks from late September into early October. Its conclusion: what looks like a single operator chained together ARTEX, an AI penetration-testing tool built in China, several large language models from different companies, and Anthropic's coding agent Claude Code. The scale of the breach — seven Korean financial firms and about 66,000 customers, according to Korean regulators and the companies — was covered in our October 7 edition. This report shows how the attack worked.
1. The evidence came from the attacker's open folders
CrowdStrike analysts found a publicly browsable directory on one server used in the attacks. A Chinese-language instruction file there pointed to a second server in Hong Kong, the main hub, which held a record of the whole operation.
| What was found | What it contained |
|---|---|
| Claude Code session logs | Instructions the attacker gave the AI coding agent, and its replies |
| ARTEX configuration files | Which models were wired in, in what order |
| AI memory files | Target information carried between sessions |
| Chinese-language prompt document | Instructions telling LLMs how to run a penetration test |
| Proxy list | Nine IP addresses used to hide the real location |
Attribution usually rests on indirect clues — malware fragments, server addresses, working hours. Here the attacker's intentions were written down, because they had to tell the AI what to do. AI made the attack easier, and it also turned the attacker's thinking into a document.
2. The toolkit — ARTEX for intrusion, several models for support
| Tool / model | Maker | Role (as reported) |
|---|---|---|
| ARTEX | Chinese developer, open source | Autonomous agent that hunts for and exploits weaknesses in specific services |
| DeepSeek v4.1-flash | DeepSeek (China) | ARTEX's main model, accessed through a reseller |
| GLM-5.3 | Zhipu AI / z.ai (China) | Helper model in additional sessions |
| Grok 4.6 | xAI (US) | Helper model in additional sessions |
| Claude Code | Anthropic (US) | Coding agent run by the attacker; session and memory logs survived |
The systems that fell were not core banking platforms. At one bank it was a loan-status lookup service used by outside loan brokers; at another, a mobile work app for employees. CrowdStrike wrote that AI tools let a single financially motivated operator break into many targets in a short time. That fits the near-simultaneous attacks on four banks from the same IP address.
The logs also show what came after. The attacker asked Claude where stolen Korean data is usually sold and how to find Korean-language Telegram groups that trade it. The same Telegram account appeared in sessions probing a Chinese payment platform and a Telegram-based NFT gift exchange.
3. Identity — one resume, but no certainty
The most striking record is a request for the AI to write a "security researcher" resume highlighting achievements with ARTEX. The prompt included a name (YY), a degree from South China University of Technology, a home in Maoming, Guangdong, an age of 26 and a Telegram handle.
| Recorded detail | Assessment |
|---|---|
| Name "YY", Telegram handle | Same handle appears in other attack sessions |
| Education, hometown | South China University of Technology; Maoming, Guangdong |
| Age | Stated as 26, but conflicts with a first-entered birth date of September 2007 |
| CrowdStrike's view | Likely the attacker's details, but not confirmed |
| Attribution | No named group; Chinese-speaking and financially motivated — moderate confidence |
After the report, the ARTEX developer (GitHub account Autumn-27) closed the source and stopped public releases, citing misuse. Copies already downloaded under the open licence still run. How liability differs between a person wielding AI as a tool, as here, and an AI agent entering systems nobody told it to touch is covered in "What AI agent legal liability means."
4. What remains and what is unconfirmed
- Parliamentary hearing: Korea's National Assembly has called the heads of the five biggest commercial banks to its annual audit on October 19. Police are investigating whether one person or a group was behind it.
- Claude's role: Public material cannot separate how much of the intrusion relied on Claude models, and an official Anthropic comment was not found. The same week, Anthropic launched a programme to defend power grids and water systems ("Anthropic Cyber Mission").
- Victim count: Korean tallies say about 66,000 customers at seven firms; foreign reports give only partial bank-by-bank numbers.
- The defensive lesson: AI sped up the attacker, but the systems that fell were peripheral — broker lookups and staff apps. Securing those to the same standard as core systems is now the sector's homework.
Sources
- The Register — CrowdStrike finds possible bank hacker's CV among exposed AI logs
- Security Affairs — AI-driven tool ARTEX used in attacks against South Korean banks
- Infosecurity Magazine — Chinese hacker deployed AI in campaign against South Korean banks
- Hankook Ilbo — Hacker behind Korean financial attacks is 26, from Guangdong
- Digital Today — CrowdStrike analyses AI hacking of Korean financial sector