The cybersecurity firm CrowdStrike said Wednesday that a recent string of cyberattacks against banks in South Korea may have been carried out by a hacker using Chinese and American artificial intelligence tools.
CrowdStrike said the attacker had used ARTEX, a recently released open source tool developed in China, and A.I. tools including Anthropic’s Claude Code in a “targeted campaign” against South Korean financial organizations between September and October. It found internet addresses and files from the tools using publicly accessible data, the firm said.
“While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated,” the company said in a report published Wednesday. It added that it had “moderate confidence” in its assessment, which it said was based on the hacker’s use of ARTEX and prompts written in Chinese.
The report comes as countries around the world are grappling with the increasing abilities of A.I. agents, raising alarm about the pace of their development and questioning whether adequate safeguards are in place for the fast-evolving technology.
In South Korea, anxiety surrounding A.I. has sent the country’s stock market on a roller-coaster ride. The nation’s benchmark Kospi index, which doubled in the first half of this year, fell quickly during the summer over concerns about the technology.
Those anxieties have risen in the past several weeks as details emerged about hacking attacks on different South Korean banks, in which the personal credit information of thousands of customers was leaked.
Earlier this week, South Korean officials said they were investigating the breaches, but provided little information about who was behind them. President Lee Jae Myung said that “signs have emerged” that A.I. models had been used in some of the cyberattacks, “causing considerable public concern and anxiety.”
The South Korean police said it had no comment on the CrowdStrike report while its investigation was underway.
CrowdStrike said in its report on Wednesday that the possible hacker its researchers tracked had on one occasion asked Claude where people go to sell stolen Korean data.
Another time, the user asked Claude to create a “security researcher résumé” and provided details such as the name “YY,” along with a phone number, age, university and the name of a Chinese city. When The New York Times called the phone number on Thursday, a man picked up the phone, speaking Chinese and using obscenities, and said he was not “YY.”
CrowdStrike said that the résumé information, including the phone number, most likely belonged to the user, but it could not say so definitively.
Despite apprehensions over the use of A.I., South Korea has largely embraced the technology and benefited from the global boom. Its monthly semiconductor exports hit a record-breaking $60.3 billion in September, more than triple compared to the same period last year, according to the government. And the nation’s gross domestic product has gone up because of it.
Choe Sang-Hun contributed reporting.
The post Hacker Used Chinese-Developed A.I. Tool to Target South Korean Banks, CrowdStrike Says appeared first on New York Times.




