CrowdStrike finds possible bank hacker's CV among exposed AI logs
Suspected Chinese speaker used Claude Code and agentic pentesting tool ARTEX in attacks on South Korean lenders
The Register reports that CrowdStrike researchers have discovered possible bank hacker credentials within exposed AI logs, possibly identifying the attacker behind recent attacks on South Korean financial institutions. The logs contained operational details and a resume-writing request, which may belong to the attacker, though CrowdStrike cannot definitively confirm this connection.
The attacks affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank. The researchers found references to the hacker, referred to as YY, in AI sessions associated with the attacks, alongside the use of ARTEX, a recently released open-source penetration-testing tool developed in China.
This incident demonstrates the evolving use of AI tooling by financially motivated threat actors to conduct multiple intrusions within a short time span.
Brief written by urgent.news from The Register's own syndicated text. Machine-written — may contain errors; check the original before relying on it.