CrowdStrike says hacker used LLMs and AI pentesting tools in attacks on South Korean financial firms

CrowdStrike says hacker used LLMs and AI pentesting tools in attacks on South Korean financial firms

N
News Editor
2026-10-08 12:55:25
CrowdStrike said in an intelligence report that an unidentified hacker combined large language models with ARTEX, a domestic open-source AI penetration testing tool, to carry out targeted cyberattacks against multiple South Korean financial institutions between late September and early October. According to the report, analysis of an exposed open directory linked to the attacker showed a dual-server setup centered on a Hong Kong IP address. CrowdStrike said the operator used Claude Code, GLM-5.3, Grok 4.6, and DeepSeek v4.1-flash accessed through an API proxy to orchestrate the attack workflow. The report also said the hacker asked Claude how to monetize leaked South Korean data in Telegram groups. Separately, South Korean media estimated that at least seven financial institutions were hit, including KB Kookmin Bank, Shinhan Bank, and Hana Bank. Around 68,000 people had personal data exposed, including sensitive details such as annual income and loan limits.

Odaily reported that cybersecurity firm CrowdStrike said in an intelligence report that an unidentified hacker combined large language models, or LLMs, with ARTEX, a domestic open-source AI penetration testing tool, to launch targeted cyberattacks against multiple South Korean financial institutions and steal data between late September and early October.

CrowdStrike said analysis of an exposed open directory tied to the attacker showed a dual-server architecture centered on a Hong Kong IP address. The report said the operator used Claude Code, GLM-5.3, Grok 4.6, and DeepSeek v4.1-flash accessed through an API proxy to coordinate the attack process. It also said the hacker had asked Claude how to monetize leaked South Korean data in Telegram groups.

South Korean media estimated that at least seven financial institutions were attacked, including KB Kookmin Bank, Shinhan Bank, and Hana Bank. About 68,000 people had personal information exposed, including sensitive data such as annual income and loan limits.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.