CrowdStrike says a suspected attacker linked to recent South Korean bank data breaches used Claude Code to ask where stolen Korean breach data is typically sold and how to locate Telegram groups that trade it. The cybersecurity firm said it found those prompts in session logs exposed through open directories on servers controlled by the attacker.

In a report published on October 7, CrowdStrike said the same infrastructure also contained configuration files for ARTEX, a Chinese-built open-source penetration testing tool, along with Claude memory files and other session histories. The company said the material offered a rare view into the operator’s workflow, tools, and apparent attempts to monetize stolen information.

Breaches disclosed by several Korean lenders

A series of incidents affected multiple South Korean banks between late September and early October. Shinhan Bank said on September 30 that it had suffered a breach, later stating that about 25,000 customers were affected.

According to the bank, the attacker bypassed identity verification on a mobile service used by loan agents to track applications. The exposed information included names, phone numbers, annual income, calculated loan limits, and 66 resident registration numbers.

Other lenders also reported smaller leaks. KB Kookmin Bank said information on 119 customers was exposed through a mobile system used by employees. Hana Bank disclosed 89 affected customers, while BNK said data concerning 11 outsourced workers had been taken.

What CrowdStrike says it found on the attacker’s servers

CrowdStrike said its researchers identified open directories on attacker-controlled systems that contained Claude Code session histories, ARTEX configuration files, and related records. A server based in Hong Kong was described as the main part of the attacker’s infrastructure, and an IP address running an ARTEX instance was considered likely to be connected to the Korean intrusions.

The report said ARTEX was the primary offensive tool in the campaign. CrowdStrike described ARTEX as an open-source penetration testing framework developed in China. It said the setup used DeepSeek v4.1-flash as the main model, while other Claude Code sessions showed use of Zhipu AI’s GLM-5.3 and xAI’s Grok 4.6.

CrowdStrike did not attribute the operation to a named group. It said, with moderate confidence, that the actor was likely a financially motivated Chinese speaker, citing the use of ARTEX and Chinese-language prompts found in the logs.

Queries about Telegram marketplaces and stolen data

Among the most notable exchanges in the exposed sessions were prompts asking Claude where threat actors usually sell Korean breach data. The user also sought help identifying Korean Telegram groups involved in selling such material.

CrowdStrike presented those requests as evidence that the operator may have been looking for ways to monetize the bank data after the intrusions. The company did not say that a sale had occurred, only that the questions appeared in the logs recovered from the exposed infrastructure.

A resume request offered possible clues

CrowdStrike said another Claude session included a request to draft a resume for a security researcher based on results achieved with ARTEX. That request listed a Telegram handle, an age of 26, and a location in Maoming, Guangdong.

The company said those details likely belong to the attacker, but it could not definitively connect them to a real identity. Researchers also noted that the same session initially included a 2007 birth date, adding another layer of uncertainty.

According to the report, the same Telegram handle appeared in other Claude Code sessions that examined a Telegram-based NFT gift marketplace for vulnerabilities.

Official response and what comes next

The bank breaches have already drawn official attention in South Korea. President Lee Jae Myung raised concerns about the role of AI in hacking during a Cabinet meeting, and police have launched a full-scale investigation.

CrowdStrike’s broader conclusion was that AI tools can help financially motivated attackers conduct several intrusions more quickly and at greater scale. For now, the confirmed next steps are the ongoing police probe and further scrutiny of how AI-assisted tools were used in the bank attacks.

Source: beincrypto.com