ARTEX developer closes source after CrowdStrike links agent to South Korean bank hacks
Since late September, South Korean financial firms have suffered a string of cyberattacks and data leaks, prompting the country's financial regulator to hold an emergency meeting and demand an investigation; CrowdStrike said on October 7 that suspected China-linked hackers were combining AI with penetration-testing tools. According to Reuters, the Chinese developer of the AI agent ARTEX — which was identified as being used to hack South Korean banks — said it has converted the project to closed source.
Why it matters: An AI agent being linked to real-world attacks and then pulled behind closed doors highlights the security and governance pressure created by agent misuse.
References Techmeme · The Information · iThome 台湾
圖片來源:
CrowdStrike
自9月底以來,韓國金融業接連發生網路攻擊與個資外洩事件,促使韓國金融主管機關召開緊急會議並要求徹查,資安業者CrowdStrike於10月7日揭露,發現疑似使用中文的攻擊者可能涉及前述事件,該攻擊者於9月底至10月初利用中國開發的AI滲透測試工具ARTEX搭配大型語言模型(LLM),攻擊韓國金融機構並竊取資料,其活動時間與針對的目標,與前述韓國金融業個資外洩事件重疊,顯示其可能與前述金融業資安事件有關。
CrowdStrike在攻擊者控制的伺服器取得Claude Code工作紀錄、ARTEX設定及Claude記憶體檔案,從中發現攻擊者曾透過Claude查詢韓國外洩資料的交易管道,並要求協助製作資安相關履歷,該攻擊者使用的ARTEX以DeepSeek v4.1-flash作為主要LLM後端,攻擊者另在Claude Code工作階段使用GLM-5.3與Grok 4.6等模型輔助。CrowdStrike認為攻擊者可能使用中文,且具有經濟動機,但僅有中等信心,尚未將活動歸因於特定攻擊組織。
How we got here
- Anthropic launches Cyber Mission, CIDP for critical infrastructure, free OSS ScannerAnthropic · News · CrowdStrike
- CrowdStrike links South Korean bank breaches to AI tool ARTEX, Claude CodeTechRepublic · ARTEX