{
  "version": 1,
  "event_id": "evt_747ad758295c5a6d",
  "url": "https://xiyu.news/events/evt_747ad758295c5a6d/",
  "json": "https://xiyu.news/api/events/evt_747ad758295c5a6d.json",
  "type": "security_incident",
  "status": "developing",
  "category": "technology",
  "title": {
    "zh": "韩国多家金融机构疑遭AI攻击，黑客在Claude Code留下身份线索",
    "en": "韩国多家金融机构疑遭AI攻击，黑客在Claude Code留下身份线索"
  },
  "current_state": {
    "zh": "韩国监管机构和 CrowdStrike 已将七家以上金融机构的数据泄露事件与一名攻击者联系起来，该攻击者使用开源代理式渗透测试框架 ARTEX，并借助 DeepSeek v4.1-flash、Claude Code、GLM-5.3 和 Grok 4.6 驱动，影响数万名客户；一名疑似 Telegram 账户否认参与。ARTEX 开发者已宣布闭源并下架 GitHub 原始仓库，但源码已被他人备份。",
    "en": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account denying involvement. The ARTEX developer has now closed the project and removed the original GitHub repository, though the source code has been backed up by others."
  },
  "first_seen_at": "2026-10-08T11:11:04.071331+00:00",
  "last_updated_at": "2026-10-09T11:20:52.110091+00:00",
  "last_material_change_at": "2026-10-09T11:20:52.110091+00:00",
  "confidence": 0.75,
  "updates_count": 2,
  "sources_count": 2,
  "entities": [
    "artex",
    "claude",
    "claude-code",
    "code",
    "github"
  ],
  "identifiers": [
    "glm-5"
  ],
  "topics": [
    "agentic-ai",
    "ai-security",
    "claude-code",
    "cyberattack",
    "financial-institutions",
    "open-source",
    "penetration-testing",
    "south-korea"
  ],
  "updates": [
    {
      "update_id": "upd_f7c93f580dc8534a",
      "event_id": "evt_747ad758295c5a6d",
      "occurred_at": "2026-10-08T10:27:02Z",
      "published_at": "2026-10-08T10:27:02Z",
      "first_seen_at": "2026-10-08T11:11:04.071331Z",
      "time_precision": "published",
      "update_type": "initial",
      "material_change": true,
      "title_zh": "韩国多家金融机构疑遭AI攻击，黑客在Claude Code留下身份线索",
      "title_en": "韩国多家金融机构疑遭AI攻击，黑客在Claude Code留下身份线索",
      "what_changed_zh": "韩国监管机构和CrowdStrike将七家以上金融机构的数据泄露事件与一名攻击者联系起来，事件影响数万名客户；该攻击者使用了由DeepSeek v4.1-flash驱动、并结合Claude Code、GLM-5.3和Grok 4.6的开源代理式渗透测试框架ARTEX，一个疑似Telegram账号目前否认参与。",
      "what_changed_en": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account now denying involvement.",
      "current_state_zh": "韩国监管机构和CrowdStrike将七家以上金融机构的数据泄露事件与一名攻击者联系起来，事件影响数万名客户；该攻击者使用了由DeepSeek v4.1-flash驱动、并结合Claude Code、GLM-5.3和Grok 4.6的开源代理式渗透测试框架ARTEX，一个疑似Telegram账号目前否认参与。",
      "current_state_en": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account now denying involvement.",
      "detailed_summary_zh": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account now denying involvement.",
      "detailed_summary_en": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account now denying involvement.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 8.0,
      "references": [],
      "confidence": 0.75,
      "story_ids": [
        "telegram:theblockbeats:199484"
      ],
      "sources": [
        {
          "url": "https://m.theblockbeats.info/flash/370801?from=telegram",
          "label": "theblockbeats",
          "source_type": "telegram",
          "official": false
        }
      ]
    },
    {
      "update_id": "upd_48639cbf3c331e98",
      "event_id": "evt_747ad758295c5a6d",
      "occurred_at": "2026-10-09T09:41:02Z",
      "published_at": "2026-10-09T09:41:02Z",
      "first_seen_at": "2026-10-09T11:20:52.110091Z",
      "time_precision": "published",
      "update_type": "response",
      "material_change": true,
      "title_zh": "卷入韩国银行AI网攻后，ARTEX作者宣布闭源，GitHub仓库已下架",
      "title_en": "卷入韩国银行AI网攻后，ARTEX作者宣布闭源，GitHub仓库已下架",
      "what_changed_zh": "ARTEX 开发者 Autumn-27 于 10 月 8 日宣布项目闭源，停止更新，不再对外发布新版本或提供维护支持；随后 GitHub 原始仓库被下架。源码已被其他开发者备份。",
      "what_changed_en": "ARTEX developer Autumn-27 announced on October 8 that the project is going closed-source, stopping updates and no longer releasing new versions or providing maintenance support; the original GitHub repository was subsequently removed. The source code has been backed up by other developers.",
      "current_state_zh": "韩国监管机构和 CrowdStrike 已将七家以上金融机构的数据泄露事件与一名攻击者联系起来，该攻击者使用开源代理式渗透测试框架 ARTEX，并借助 DeepSeek v4.1-flash、Claude Code、GLM-5.3 和 Grok 4.6 驱动，影响数万名客户；一名疑似 Telegram 账户否认参与。ARTEX 开发者已宣布闭源并下架 GitHub 原始仓库，但源码已被他人备份。",
      "current_state_en": "South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account denying involvement. The ARTEX developer has now closed the project and removed the original GitHub repository, though the source code has been backed up by others.",
      "detailed_summary_zh": "After CrowdStrike found that attackers behind a wave of intrusions into South Korean financial institutions had used the open-source multi-agent AI penetration-testing tool ARTEX, its developer closed the project and removed the original GitHub repository.",
      "detailed_summary_en": "After CrowdStrike found that attackers behind a wave of intrusions into South Korean financial institutions had used the open-source multi-agent AI penetration-testing tool ARTEX, its developer closed the project and removed the original GitHub repository.",
      "background_zh": "",
      "background_en": "",
      "community_discussion_zh": "",
      "community_discussion_en": "",
      "market_impact_zh": "",
      "market_impact_en": "",
      "importance_score": 7.0,
      "references": [],
      "confidence": 0.95,
      "story_ids": [
        "telegram:theblockbeats:199677"
      ],
      "sources": [
        {
          "url": "https://m.theblockbeats.info/flash/370996?from=telegram",
          "label": "theblockbeats",
          "source_type": "telegram",
          "official": false
        }
      ]
    }
  ]
}
