推文
@pirrer · 2026-10-11 16:33
In late September and early October, a string of South Korean financial firms disclosed data leaks. On Oct. 7, @CrowdStrike published a report on an unknown attacker who used ARTEX, an open-source AI penetration-testing agent that a Chinese developer posted on GitHub this year, to target South Korean financial organizations during that period. According to the report, the attacker also used Claude Code, a coding tool from @AnthropicAI, and left tool configurations and session logs in open directories on two servers the attacker controlled. Shinhan Bank disclosed first. A service that lets loan brokers check on applications was breached, exposing names, phone numbers, and annual incomes of about 25,000 customers. At KB Kookmin Bank, it was a mobile work system for employees. Hana Bank, BNK Busan Bank, two savings banks, and Hyundai Capital were also reported breached. As of Oct. 5, Korean media listed seven financial firms with confirmed leaks. Their disclosed figures total roughly 66,000 people, plus up to 2,200 corporate-customer records, or about 68,000 if combined. That is not an official total. CrowdStrike does not say this attacker hit all seven. Its report says organizations targeted in this activity overlap with those identified in industry reporting, while the number of organizations affected remains unconfirmed. JoongAng Ilbo reports that from intrusion to detection, Shinhan took about 15 hours, Hana about 42, and KB Kookmin about 68. President Lee Jae Myung ordered a thorough investigation. One server hosted ARTEX and an instruction file, written in Chinese, telling an AI how to run a penetration test. CrowdStrike says this ARTEX instance mainly ran on DeepSeek. A second server held Claude Code session logs. In them, the attacker asks where stolen Korean data is typically sold and for help finding Telegram groups that sell it. In another session, the attacker asks for a security researcher résumé with bullet points on the results of the ARTEX activity. The prompt gives a name, YY, a Telegram handle, an age of 26, South China University of Technology, and Maoming, in China’s Guangdong province. The first birth date supplied was in 2007, which doesn’t match 26. CrowdStrike says it can’t confirm those details belong to the attacker. Reuters called the phone number in the report, and the man who answered said he knew nothing about it. CrowdStrike assesses, with moderate confidence, that the attacker likely speaks Chinese and is financially motivated. It hasn’t attributed the activity to any named adversary. The day after the report, ARTEX’s developer said it would go closed-source, and Reuters found its GitHub page gone.
曝光 523 · 评论 1 · 点赞 1 · 书签 0 · 曝光/时 89.71789051678302