A campaign targeting South Korea's financial sector has provided unusually clear evidence of how artificial intelligence can be integrated into a real intrusion workflow. According to the reported findings, a Chinese-speaking attacker used the ARTEX AI penetration-testing suite alongside Claude-based agents and several language models while targeting institutions including Shinhan Bank, KB Kookmin Bank and Hana Bank.
AI Moves Into the Attacker's Workbench
Security researchers reportedly found open directories containing ARTEX configuration files, Claude Code session histories and memory files. Those records offered a window into how the attacker combined automated reasoning with conventional offensive tools. DeepSeek was reportedly used as a primary model, while additional sessions involved models from Zhipu AI and xAI.
The importance of this case is not that an AI system independently compromised a bank. Instead, it shows how one operator can use several models to support reconnaissance, troubleshooting, scripting and decisions during an intrusion. The same exposed records reportedly connected the infrastructure to attacks that affected banking systems and exposed personal or credit-card information.
Operational Security Failed the Attacker
The attacker's AI environment also became a source of intelligence for defenders. Session records apparently included personal details, contact information and a resume, although researchers cautioned that this material was insufficient to confirm the person's identity. The records also suggested that the operator asked an AI assistant to identify possible Telegram channels where stolen Korean data could be sold.
What Financial Institutions Should Do
- Monitor for automation frameworks and command patterns associated with AI-assisted offensive testing.
- Correlate identity, endpoint, network and application telemetry instead of investigating each alert separately.
- Apply stricter controls to externally exposed services and administrative interfaces.
- Run incident exercises that assume attackers can automate reconnaissance and exploit development.
In my view, the defensive lesson is not to search for a unique AI malware signature. Organizations should expect established attack techniques to arrive faster and with fewer human errors. Security teams will need automated containment, high-quality telemetry and rapid validation processes if they want to keep pace with attackers using multiple AI systems as force multipliers.
