Global security firm CrowdStrike said on Oct. 7 it analyzed an AI-powered hacking incident that recently hit South Korea’s financial sector and found that a hacker believed to be a Chinese-language user leaked data using an AI agent-based hacking tool.
According to CrowdStrike’s threat analysis unit, CrowdStrike Intelligence, the attacks continued from late September to early October. The hacker used the China-developed open-source penetration testing tool ARTEX together with a large language model (LLM).
CrowdStrike said it found Claude code session logs, ARTEX configuration files and Claude memory files in a public directory on a server controlled by the hacker. It added that one server also contained a Chinese-language prompt document instructing an LLM on how to conduct penetration testing.
The hacker used a Hong Kong-based server as a main base and ran ARTEX on other servers. ARTEX appeared to have used DeepSeek v4.1-Flash as its main LLM.
The hacker also used z. AI GLM-5.3 and Grok 4.6. The attack went through 9 proxy IP addresses. A proxy IP is a server address used as an intermediary to hide a hacker’s real location.
CrowdStrike’s analysis found that the hacker asked Claude where Korean hacking information is mainly sold and requested help finding ways to trade such information on Telegram.
Records also showed the hacker entered personal details such as a name, educational background and place of residence while requesting the creation of a security researcher resume detailing ARTEX attack results. CrowdStrike said the information was likely the hacker’s own but was difficult to link definitively.
CrowdStrike did not identify the attacker as belonging to any specific organization. It assessed the attacker was a Chinese-language user and likely had a financial motive. The company said, "Thanks to AI tools, financially motivated attackers were able to conduct multiple intrusions in a short period," and added, "Attackers will keep trying to adopt AI tools to increase operational speed and capability."