Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

AI Tools and Sloppy Opsec Expose Suspected Chinese Hacker Behind South Korean Bank Breaches

Дата публикации: 09-10-2026 00:22:15

CrowdStrike uncovered exposed AI logs from a suspected Chinese hacker who used ARTEX and Claude to breach multiple South Korean banks. The logs contained a resume request with personal details plus queries about selling stolen data on Telegram. At least five lenders reported customer records compromised in the late September to early October campaign.

Основное содержимое страницы с новостью.

A single attacker. Multiple South Korean banks. Stolen customer records by the tens of thousands. And the trail that led investigators back to him sat wide open on his own servers.

CrowdStrike uncovered the campaign while examining attacks on financial institutions that began in late September 2026 and continued into early October. The intrusions hit loan inquiry services used by brokers and employee mobile work-support systems. Data taken included names, phone numbers, income details, loan limits and, in some cases, South Korea’s resident registration numbers.

Exposed Logs Reveal Attacker’s Toolkit and Identity Clues

Researchers found attacker-controlled servers with open directories. Those folders contained Claude Code session histories, configuration files for a tool called ARTEX, and memory files from Anthropic’s AI coding assistant. The visibility proved unusual. It gave direct insight into prompts, chosen models and operational flow.

The attacker relied heavily on ARTEX, an open-source agentic penetration-testing platform developed in China. It ran primarily on DeepSeek v4.1-flash. Other sessions pulled in GLM-5.3 from Zhipu AI and Grok 4.6. Prompts appeared in Chinese. References to “YY” surfaced across sessions tied to the banking activity. One prompt asked Claude to draft a security researcher resume.

That resume request listed a Chinese university, a location in Guangdong province, a Telegram username and an age of 26. An earlier birth date in the logs pointed to September 2007, creating an inconsistency. CrowdStrike analysts, led by Ashley Campion, assessed the details likely belonged to the perpetrator. They stopped short of absolute confirmation. The same Telegram handle appeared in other activity targeting a possible Chinese payment platform and a Telegram-based NFT gift marketplace.

But the logs went further. The attacker asked Claude where threat actors sell stolen Korean breach data. He sought Korean Telegram groups active in such transactions. Financial motive appeared clear. “The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft,” Campion said, according to The Register.

At least five lenders disclosed breaches: Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank. Shinhan reported roughly 25,000 customers affected. Other counts varied. Yegaram Savings Bank saw exposure for about 40,000 people in some tallies. KB Kookmin cited 119. Hana and BNK reported smaller numbers. Reuters counted at least nine banks targeted since late September, per The Next Web. South Korean police opened investigations. President Lee Jae-myung raised the AI angle in a cabinet meeting.

The campaign moved fast. Late September to early October. One operator. Multiple intrusions. That speed stands out. Agentic tools appear to shrink the time from reconnaissance to execution. ARTEX, released recently on GitHub by a security engineer known as Autumn, acts as a bridge to large language models. It automates probing for weaknesses. The attacker pointed it at weaker external services rather than core banking systems.

Yet the exposure of those very logs points to basic errors. Open directories on infrastructure tied to Hong Kong and IP address 38.244.50.120. Files left accessible. Chat histories unencrypted. Opsec failures like these have doomed sophisticated actors before. This time they handed investigators the attacker’s own words.

Bloomberg reported the suspect may have operated from China, citing the Guangdong clues and tool origins. Yonhap News Agency quoted CrowdStrike’s moderate-confidence assessment: Chinese speaker, financially motivated, no link to a named group. The firm stressed the activity has not been attributed to any established adversary.

Questions remain. Exact number of victims. Full scope of data taken. Whether the personal details tie definitively to the operator. A Reuters reporter dialed a phone number linked in the logs; the man who answered claimed no knowledge. Conflicting age data in the resume prompt adds doubt. Still, the overlap across sessions, infrastructure and targets builds a coherent picture.

Financial institutions worldwide now face a new variable. Large language models and agentic pentesting tools lower barriers. A motivated individual can scan for weaknesses, generate code, research monetization paths and iterate quickly. The same models that help developers can assist attackers. And when those attackers store session data on public-facing servers, defenders gain rare visibility.

South Korean authorities issued consumer alerts. Banks notified customers. Regulators examine controls around broker portals and mobile employee systems. The breaches exposed sensitive personal data that could fuel identity theft, loan fraud or sales on underground markets.

CrowdStrike published indicators of compromise drawn from the exposed servers. Security teams can hunt for the Hong Kong infrastructure and related IPs. Yet the broader lesson sits elsewhere. Tools once reserved for red teams or nation-state actors now appear in the hands of profit-driven operators. Their mistakes create openings for researchers. But the next campaign may not leave logs behind.

So the exposure of a would-be security researcher’s resume inside his own attack artifacts carries irony. The very AI assistant he queried for career help helped expose him. And the open directory that betrayed him offers a cautionary record of how quickly one person, armed with recent open-source projects and commercial models, can pressure an entire sector’s defenses.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Chinese AI Agent Pulled From Public View After Breaching South Korean Banks011.6409-10-2026
2CrowdStrike Says South Korean Bank Hack Suspect May Be a 26-Year-Old Using ARTEX and Claude Code08.7308-10-2026
3Китайский хакер взломал банки Южной Кореи с помощью искусственного интеллекта07.9808-10-2026
4South Korea’s Banks Under AI-Assisted Assault: President Lee Demands Answers015.8508-10-2026
5Кибератака с ИИ: китайскоязычный хакер взломал системы банков Южной Кореи07.9508-10-2026
6Un agent IA offensif industrialise les compromissions : autopsie des attaques ARTEX08.6508-10-2026
7Chinese developer makes ARTEX AI agent closed-source after Korean bank hack 09.0709-10-2026
8Suspect behind South Korea bank hacks may be 26-year-old in China, CrowdStrike says 06.1408-10-2026
9Хакеры атаковали банки Южной Кореи, утекли данные десятков тысяч клиентов07.0402-10-2026
10When AI Agents Turn on Their Masters: Hackers Lose Email Harvest to Rogue Security Tools08.3502-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.33. Источник: www.webpronews.com.