攻击者入侵韩国银行后曾询问 Claude 在哪里出售窃取的韩国数据。官员认为一个开源中国智能体帮助攻击了至少 7 家韩国金融机构,其 Claude Code 会话历史、Claude 记忆文件和 ARTEX 配置留在开放目录中。
The attacker who breached South Korean banks asked Claude where stolen Korean data sells.
And Officials believe an open-source Chinese agent helped breach at least 7 South Korean financial institutions.
The attacker’s own Claude Code session histories, Claude memory files and ARTEX configurations sat in open directories, giving a direct view of how an AI-assisted intrusion campaign against South Korean finance was run.
ARTEX, a recently released Chinese open-source agentic pentesting tool, ran on DeepSeek v4.1-flash, likely reached through an API reseller, from a host that probably carried out the Korean attacks.
来源:Rohan Paul · x.com