Claude Code駭客評測:南韓銀行外洩,AI日誌出賣真凶 | Claude Code Hacker Review: AI Logs Exposed the Suspect
By Kit 小克 | AI Tool Observer | 2026-10-09
🇹🇼 Claude Code駭客評測:南韓銀行外洩,AI日誌出賣真凶
資安公司 CrowdStrike 於10月7日公布報告,指出一名可能位於中國廣東的駭客,利用 Anthropic 的 Claude Code 搭配中國自製的 AI 滲透測試工具 ARTEX,在9月下旬到10月初短短兩週內攻擊了至少九家南韓銀行,外洩6.8萬人的個資。這是目前文件記載最完整的一起「AI 程式代理被用於真實攻擊」案例,但更諷刺的是:抓到他的關鍵線索,也來自同一套 Claude Code 對話紀錄。
Claude Code 在這起攻擊裡扮演什麼角色
根據 CrowdStrike 的分析,駭客並沒有直接靠 Claude 模型本身的能力執行攻擊邏輯,而是把 Claude Code 當成一個「代理人外殼」(agent harness)。背後真正負責推理、寫程式的模型其實是 DeepSeek v4.1-flash,再搭配 GLM-5.3 與 Grok 4.6 支援。換句話說,Claude Code 提供的是工具呼叫迴圈與操作介面,駭客把便宜、限制較少的第三方模型接上這套殼,拿來寫攻擊腳本、調度 ARTEX 掃描南韓金融機構。
這個細節很重要:這次事件曝光的不是「Claude 模型被攻破去害人」,而是「AI 代理框架本身是模型無關的(model-agnostic),換一個後端一樣能拿來幹壞事」。看到類似新聞標題時,先分清楚這兩種情況,防禦重點完全不同。
真正讓他栽了的,是自己留在 Claude Code 裡的紀錄
CrowdStrike 在駭客使用的香港伺服器上,找到一個沒有設密碼保護的開放目錄,裡面完整留著 Claude Code 的對話歷史、ARTEX 設定檔,以及 Claude 的記憶檔案。從紀錄可以看到,駭客曾請 Claude 幫他起草一份「資安研究員」履歷,裡面寫進了26歲、畢業於華南理工大學、廣東等個人資訊;他也問過 Claude 該去哪裡在 Telegram 上兜售偷來的南韓銀行資料。這些原本只是攻擊者圖自己方便留下的筆記,最後卻變成 CrowdStrike 拼出身份的關鍵證據。
對開發者與企業的實際啟示
- 把 AI 代理的對話紀錄當成敏感資料來管理,等級不輸瀏覽器歷史或 shell history,別留在沒有存取控制的伺服器或目錄裡。
- 看到「AI 被用於攻擊」的新聞,先確認是模型本身被濫用,還是代理框架被接上別的後端模型,兩者的防禦策略不一樣。
- 企業資安防線應多留意 ARTEX 這類 AI 滲透測試工具留下的攻擊特徵,而不是只盯著某一家 AI 公司的模型。
Anthropic 目前尚未對此事件做出完整的公開技術回應,CrowdStrike 這份報告也只以中等信心程度將身份指向這名廣東人士,細節仍可能隨調查修正。
好不好用,試了才知道。
🇺🇸 Claude Code Hacker Review: AI Logs Exposed the Suspect
Security firm CrowdStrike reported on October 7 that a hacker likely based in Guangdong, China used Anthropic's Claude Code alongside a Chinese-built AI pentesting tool called ARTEX to breach at least nine South Korean banks, exfiltrating personal data belonging to 68,000 people in just two weeks, from late September to early October 2026. It is one of the best-documented cases yet of an AI coding agent being used inside a real attack chain — and ironically, the same Claude Code logs are what helped expose the suspect.
What Claude Code Actually Did in This Attack
Per CrowdStrike, the attacker did not rely on Claude's own model to drive the attack logic. Instead, Claude Code served as an agent harness — the tool-calling loop and interface — while the actual reasoning and code generation were handled by DeepSeek v4.1-flash, supplemented with GLM-5.3 and Grok 4.6. In other words, the attacker swapped a cheaper, less-restricted backend model into Claude Code's shell to write attack scripts and orchestrate ARTEX scans against Korean financial institutions.
That distinction matters. This is not a story about Claude's model being broken into helping an attacker — it is a story about agent frameworks being model-agnostic, so any backend can be plugged in for malicious use. When a headline says AI was used in an attack, check which of the two it actually means, because the defensive response differs.
His Own AI Logs Gave Him Away
CrowdStrike found an open, unprotected directory on the attacker's Hong Kong server containing full Claude Code conversation history, ARTEX config files, and Claude memory files. The logs showed the attacker asking Claude to draft a security researcher resume listing personal details — age 26, a degree from South China University of Technology, and a Guangdong location — and separately asking where on Telegram he could sell the stolen Korean bank data. Notes he left for his own convenience became the evidence that let CrowdStrike piece together his identity.
What This Actually Means for Developers and Teams
- Treat AI agent session logs as sensitive data, on par with browser or shell history — never leave them in directories without access control.
- When a headline claims AI was used in an attack, check whether the model itself was abused or just the agent harness ran a different backend — the two call for different defenses.
- Security teams should watch for the attack patterns of agentic pentesting tools like ARTEX specifically, rather than assuming a single AI vendor's model is the weak link.
Anthropic has not yet issued a full technical response, and CrowdStrike itself only attributes the identity with medium confidence — details may still shift as the investigation continues.
Good or not, you won't know until you try it.
Sources / 資料來源
- CrowdStrike: Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
- The Register: CrowdStrike finds possible bank hacker's CV among exposed AI logs
- Infosecurity Magazine: Chinese Hacker Deployed AI in Campaign Against South Korean Banks
延伸閱讀 / Related Articles
- macOS Full Disk Access評測:蘋果對AI代理收權限 | macOS Full Disk Access Review: Apple Curbs AI Agents
- AI蠕蟲評測:OpenAI證實提示注入會自我複製 | AI Worms Review: OpenAI Confirms Prompt Injection Spreads
- Pi 1.0評測:硬剛MCP一年的AI代理終於妥協 | Pi 1.0 Review: The Coding Agent That Hated MCP Ships It
AI 工具觀察站 — 每日精選 AI Agent 與工具趨勢
AI Tool Observer — Daily curated AI Agent & tool trends
留言
張貼留言