Key points
- CrowdStrike found the attacker's AI chat logs
- DeepSeek powered the attacker's ARTEX tool
- A résumé request pointed to southern China
CrowdStrike (CRWD) says an attacker targeting Korean financial companies used Anthropic's Claude Code and a DeepSeek model. The US security company published its findings on Oct. 7 and assessed with moderate confidence that the attacker is likely a Chinese speaker motivated by money. It hasn't linked the attacks to any known hacking group.
It's the first clue to the attacker's identity since the breaches began, Yonhap News Agency (연합뉴스) reported. Seven Korean financial companies have confirmed breaches since late September, including Shinhan Bank (신한은행), KB Kookmin Bank (KB국민은행) and Hana Bank (하나은행). I wrote about the seven breaches on Oct. 4 and the president's warning on Oct. 6.
The attacker left AI chat logs on open servers
CrowdStrike found servers controlled by the attacker with directories anyone could browse. They held Claude Code session histories, Claude memory files and settings files for ARTEX, an open-source tool developed in China. ARTEX uses AI agents to automate penetration testing, or checking computer systems for weaknesses. The files indicate the attacker targeted Korean financial companies from late September to early October.
The attacker ran the operation from a server in Hong Kong and kept the copy of ARTEX likely used against the Korean companies on a second server, according to CrowdStrike. The attacker also routed connections through nine proxy addresses.
DeepSeek's lightweight model ran the hacking tool
ARTEX ran mainly on DeepSeek V4.1-Flash, a lightweight model DeepSeek released on Sept. 10. The attacker likely reached it through a third-party reseller rather than through DeepSeek itself. In other Claude Code sessions, the attacker also used Zhipu AI's GLM-5.3 and Grok 4.6.
The attacker also asked Claude where hackers usually sell data stolen in Korean breaches, and asked for help finding Korean Telegram groups that sell such data.
A résumé request pointed to southern China
In one session, the attacker asked Claude to write a security researcher's résumé that included the results of the attacks. The details entered included a Telegram account, an education history, an age of 26 and a location in Maoming, a city in China's Guangdong province. The same Telegram name appeared in sessions probing a Telegram-based NFT marketplace and in activity targeting what may be a Chinese payment platform.
The same request initially listed a 2007 birth date, which doesn't match that age. CrowdStrike says the details likely belong to the attacker, though it could not confirm the connection.
The Korean National Police Agency's cyber investigation bureau (경찰청 사이버수사국) is investigating the attacks, after traces of ARTEX turned up at an internet address used against the banks.












