跳到正文
The Decoder· Matthias Bastian·· 4 小时前精选AI 评分78

AI 渗透工具 ARTEX 疑助单名攻击者攻破多家韩国银行

AI-powered hacking tools enabled a likely single attacker to breach multiple South Korean banks

AI 导读

CrowdStrike 报告称,一名疑似中文使用者于 2026 年 9 月底至 10 月初攻击多家韩国金融机构,窃取大量数据,其中 Shinhan Bank 超过 25,000 条包含姓名、联系方式、收入和信用额度的记录被窃。

推荐理由

原文给出单名攻击者借助开源 AI 渗透测试工具攻破多家韩国银行的具体细节,读者可以了解 AI 工具带来的现实攻击门槛变化。

正文 · 原文

Crowdstrike reports on an infrastructure hack in South Korea. A suspected Chinese-speaking attacker hit multiple South Korean financial institutions between late September and early October 2026, stealing large amounts of data. At Shinhan Bank alone, more than 25,000 records with names, contact details, income, and credit limits were stolen, according to Korean newspaper Khan. South Korea's financial regulator held an emergency meeting. President Lee Jae Myung called for a thorough investigation.

The attacker used ARTEX, a Chinese open-source tool first posted on GitHub in July that uses AI language models for automated penetration testing, meaning it finds security flaws on its own. The models behind it were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Researchers found Claude Code session logs on the attacker's open directories, showing searches for Telegram groups to sell stolen data.

Crowdstrike says the case shows how AI tools can let a single person pull off massive breaches in a short window, the kind of cybersecurity risk experts have been warning about for months. Just days earlier, Anthropic documented that GLM-5.3 can write exploits nearly on par with Mythos Preview, Anthropic's frontier model and the one that sparked the entire debate in late March 2026.

AI News Without the Hype – Curated by Humans

Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.

来源:The Decoder · the-decoder.com