Create

Sign in to ReadmeX

or

How we handle your data: Privacy Policy

ReadmeX
ReadmeX

A clearer picture, in a conversation.

Catch up on what matters, then ask a little deeper.

Your community and people briefings stay personal to you.

Story

ARTEX developer closes source after CrowdStrike links agent to South Korean bank hacks

AI summary

Since late September, South Korean financial firms have suffered a string of cyberattacks and data leaks, prompting the country's financial regulator to hold an emergency meeting and demand an investigation; CrowdStrike said on October 7 that suspected China-linked hackers were combining AI with penetration-testing tools. According to Reuters, the Chinese developer of the AI agent ARTEX — which was identified as being used to hack South Korean banks — said it has converted the project to closed source.

Why it matters: An AI agent being linked to real-world attacks and then pulled behind closed doors highlights the security and governance pressure created by agent misuse.

ARTEXCrowdStrike

References Techmeme · The Information · iThome 台湾

17
Source textiThome 台湾 · 1 min read

圖片來源: 

CrowdStrike

自9月底以來,韓國金融業接連發生網路攻擊與個資外洩事件,促使韓國金融主管機關召開緊急會議並要求徹查,資安業者CrowdStrike於10月7日揭露,發現疑似使用中文的攻擊者可能涉及前述事件,該攻擊者於9月底至10月初利用中國開發的AI滲透測試工具ARTEX搭配大型語言模型(LLM),攻擊韓國金融機構並竊取資料,其活動時間與針對的目標,與前述韓國金融業個資外洩事件重疊,顯示其可能與前述金融業資安事件有關。

CrowdStrike在攻擊者控制的伺服器取得Claude Code工作紀錄、ARTEX設定及Claude記憶體檔案,從中發現攻擊者曾透過Claude查詢韓國外洩資料的交易管道,並要求協助製作資安相關履歷,該攻擊者使用的ARTEX以DeepSeek v4.1-flash作為主要LLM後端,攻擊者另在Claude Code工作階段使用GLM-5.3與Grok 4.6等模型輔助。CrowdStrike認為攻擊者可能使用中文,且具有經濟動機,但僅有中等信心,尚未將活動歸因於特定攻擊組織。

Read the original →

How we got here

  1. Anthropic launches Cyber Mission covering critical infrastructure and open sourceAnthropic · News · CrowdStrike
  2. CrowdStrike links South Korean bank breaches to AI tool ARTEX, Claude CodeTechRepublic · ARTEX

Comments

I've used this: share my experience What I think: share my view
How important is this story?No ratings yet

No comments yet. Start the conversation.