China-Based Hacker Used AI Agent Claude Code to Target South Korean Banks: CrowdStrike

چین سے منسلک ہیکر کی جنوبی کوریا کے بینکوں پر حملوں میں اے آئی ایجنٹ 'کلاؤڈ کوڈ' کی تخریب کاری

China-Based Hacker Used AI Agent Claude Code to Target South Korean Banks: CrowdStrike

A US cybersecurity company CrowdStrike has alleged that the cyberattacks on South Korean banks were orchestrated by a 26-year-old, who used a locally developed AI agent alongside Anthropic's Claude Code to secure access into the banks' systems. CrowdStrike says that it discovered the personal details of the hacker while analysing the AI coding tool sessions and infrastructure used in the hacking campaign and revealed that the suspect was likely operating from China's Guangdong province.

Earlier, South Korean police launched a probe after at least nine banks revealed that their systems were targeted in a hacking attempt in late September. The attacks have prompted South Korean President Lee Jae-myung to call for robust response measures to protect the national financial infrastructure from further digital threats.

Shinhan Bank said that personal information of their 25,000 customers was leaked while KB Kookmin Bank revealed that personal information of 119 customers was compromised during the hacking attempt. The scale of the breach has raised concerns among financial regulators regarding the security of digital banking platforms in the region.

"It was an example of a human adversary leveraging AI agents to conduct widespread attacks," Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told reporters via a telephonic conversation on Thursday. He emphasized that the integration of AI tools significantly lowers the barrier for entry for cybercriminals.

He said, "This is significant because it allows one human to target many customers in a very short period of time using the power of AI." CrowdStrike did not name the attacker directly but suspected that a Chinese speaker was involved who used China's locally developed open-source penetration tool ARTEX to get access into South Korean banks.

The attacker reportedly asked Claude Code to prepare a cybersecurity resume and supplied personal information, including an age of 26, educational background and a location in Maoming, Guangdong. CrowdStrike cautioned that these details could not definitively identify the hacker, as they might be fabricated to mislead investigators.

The US cybersecurity company alleged that the attacker likely wanted to sell the personal data of customers as he asked Claude to help them find the right market for the data stolen through the breach. This incident highlights the growing trend of using generative AI to automate malicious activities.

Security experts are now urging banks to implement multi-factor authentication and advanced behavioral monitoring to detect AI-driven anomalies. The South Korean government is currently coordinating with international cybersecurity agencies to track the origin of the attack and prevent future occurrences.

As the investigation continues, the focus remains on how AI agents can be restricted from assisting in illegal activities. Anthropic has not yet issued a detailed statement regarding the specific misuse of their Claude Code platform in this incident.

The global cybersecurity community is closely monitoring this case, as it represents a shift in how sophisticated cyber threats are evolving. The use of AI in this campaign suggests that future attacks will likely become more automated and harder to trace for traditional security systems.

Related coverage