CrowdStrike researchers have uncovered a fascinating intersection of modern dev tooling and cybercrime. In an investigation into attacks on South Korean financial institutions, analysts discovered exposed AI session logs that contained operational details and a resume-writing request. These logs, generated by tools like Claude Code and the open-source pentesting framework ARTEX, provided enough context to potentially identify the attacker, a suspected Chinese speaker. This incident serves as a stark reminder that the tools we use to build software are also being weaponized to break it, often leaving digital fingerprints in places developers least expect.
The Artifact Trail
The investigation, led by analyst Ashley Campion, traced the attacks to a server directory containing Chinese-language instruction files. These files pointed to a second server in Hong Kong hosting session histories, configuration files, and AI memory files. One specific prompt named "YY," listed a Chinese university, and specified a location in Guangdong. The prompt also included conflicting age data, stating the individual was 26 but providing a birth date in September 2007. While CrowdStrike cannot definitively link these details to the attacker, the correlation with activity involving ARTEX and Claude Code is strong.
Agentic Tooling in the Wild
The attackers utilized ARTEX, a recently released open-source penetration-testing tool developed in China, alongside Anthropic's Claude Code. This combination allowed for a high operational tempo, enabling multiple intrusions in a short span. Campion noted that the use of agentic AI tooling alongside traditional offensive capabilities highlights the evolution of adversarial tradecraft. The logs revealed references to a Telegram username that appeared in other contexts, including targeting a possible Chinese payment platform and seeking vulnerabilities in a Telegram-based NFT gift marketplace.
Operational Impact and Response
The breaches affected at least five lenders, including Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank, and BNK Busan Bank. Shinhan Bank reported that approximately 25,000 customers were affected, while KB Kookmin and Hana Bank reported 119 and 89 customers respectively. In one instance, attackers breached a loan progress inquiry service, and in another, they accessed a mobile work-support system. South Korean lawmakers have approved plans to summon the heads of five major commercial banks to an October 19 parliamentary audit to address these cybersecurity lapses.
Key Takeaways
- Agentic AI tools like Claude Code and ARTEX are being actively used by threat actors to accelerate pentesting and intrusion workflows.
- Exposed session logs and AI memory files can inadvertently leak PII and operational context, aiding attribution efforts.
- The integration of open-source Chinese pentesting tools with LLMs demonstrates a growing trend in adversarial tooling evolution.
- South Korean financial institutions face increased scrutiny, with parliamentary audits scheduled for October 19 following breaches affecting thousands of customers.
The Bottom Line
Developers and security teams must treat AI session logs and memory files as sensitive artifacts with the same rigor as source code or credentials. The leak of a 'resume prompt' from a threat actorβs Claude Code usage proves that convenience features in agentic tools are now significant attribution vectors for defenders.