AI

Hacker used ARTEX AI and Claude agents to hit South Korean banks

CrowdStrike confirmed the ARTEX AI penetration testing suite was used in attacks on Shinhan, KB Kookmin and Hana that exposed personal data.

A Chinese-speaking hacker used the ARTEX AI penetration testing suite alongside Claude agents to launch cyberattacks on South Korean banks, including Shinhan Bank, KB Kookmin Bank and Hana Bank, exposing personal and credit card data and causing system outages. The attacks took place earlier this month, according to bleepingcomputer.com.

CrowdStrike confirmed that ARTEX AI was used in the attacks. Researchers also found open directories containing Claude Code session histories, ARTEX configuration files and Claude memory files.

The ARTEX instance relied on DeepSeek v4.1-flash as its primary LLM backend, supplemented with GLM-5.3 and Grok 4.6.

After confirming the tool had been used in real-world attacks, the ARTEX developer made the project closed-source and discontinued updates.

Quick answers

Which banks were targeted in the ARTEX AI attacks?

Shinhan Bank, KB Kookmin Bank and Hana Bank were among the South Korean banks targeted, with personal and credit card data exposed and system outages reported.

What AI models did the ARTEX instance use?

The ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend, supplemented with GLM-5.3 and Grok 4.6.

What happened to the ARTEX project?

After the developer confirmed real-world use, ARTEX was made closed-source and updates were discontinued.

Source