
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

U.S. cybersecurity firm CrowdStrike said an unidentified hacker believed to be a Chinese speaker used artificial intelligence (AI)-powered hacking tools to breach multiple Korean financial institutions and steal data.
Summary
In a report released Wednesday (U.S. time), CrowdStrike said the attacker used ARTEX, an open-source AI-powered penetration-testing tool developed in China, alongside large language models (LLMs) to carry out cyberattacks between late September and early October. The findings come amid a series of data breaches at Korean financial institutions, including Hana Bank, KB Kookmin Bank and Shinhan Bank, prompting financial authorities and investigators to launch probes into the incidents. According to CrowdStrike, the compromised systems included a bank's loan inquiry service used by financial brokers and another bank's mobile work-support system for employees.
"While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," CrowdStrike said in the report.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.