Skip to content
Rush Commerce
Software & Dev3 min read

Claude Code ran on DeepSeek in the Korean bank hacks

CrowdStrike found the Korean bank attacker drove Claude Code with DeepSeek, GLM, and Grok via a reseller proxy. Pin your coding agent's endpoint.

The attacker behind the recent South Korean bank breaches used Claude Code — but not on Claude. CrowdStrike's report says the actor ran the ARTEX AI pentest suite on DeepSeek v4.1-flash, and used GLM-5.3 and Grok 4.6 in more Claude Code sessions. DeepSeek access likely came through an LLM API reseller. The lesson for anyone running coding agents: the harness and the model are separate parts, and the model is one setting away from being someone else's.

What actually happened

Per CrowdStrike's October 7 write-up, with follow-up reporting from BleepingComputer today:

  • Timeframe: the campaign ran from late September to early October 2026.
  • The evidence: open directories the attacker controlled held Claude Code session histories, ARTEX configuration files, and Claude memory files. A CLAUDE.md file held a Chinese-language pentest prompt.
  • The models: ARTEX used DeepSeek v4.1-flash as its main backend. GLM-5.3 (Zhipu AI) and Grok 4.6 ran in other Claude Code sessions. CrowdStrike says the actor likely reached DeepSeek through xcai[.]pro, which it calls a likely LLM API proxy or reseller.
  • The targets: a loan-progress inquiry service used by brokers at one bank, and an employee mobile work-support system at another. That matches the side-system pattern we covered on October 5.
  • Attribution: none. CrowdStrike has moderate confidence the actor is a Chinese speaker with a financial motive.
  • The tool: ARTEX's developer made the project closed-source and stopped updates, but English and Korean derivatives already exist.

Why it matters for your business

Coding agents are now standard equipment, for attackers too. A model vendor's safety controls cover that vendor's model. Point the same harness at a cheaper backend and those controls are not in the request path.

The same pattern shows up on your side, minus the crime. A developer finds a reseller selling "Claude-compatible" tokens at half price. Claude Code reads its API endpoint from an environment variable. One change, and your source code, your .env reads, and your customer data in test fixtures all go to a company you have never heard of.

What we do:

Pin the endpoint. Set the API base URL and allowed models in managed config that developers can't override. Block unknown LLM hosts at the network edge.

Treat agent history as sensitive data. This attacker got caught because session logs and memory files sat in an open directory. Yours hold prompts, file contents, and sometimes secrets. Keep them out of shared drives and public buckets.

Audit your side systems. The broker portal and the staff app got hit, not the core ledger. Inventory everything internet-facing, not just the crown jewels.

Key takeaways

  • CrowdStrike found Claude Code session histories, ARTEX configs, and Claude memory files in the Korean bank attacker's open directories
  • The backend models were DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6, with DeepSeek likely reached through a reseller proxy
  • A coding agent's harness and model are separate; vendor safety controls stop at the vendor's own model
  • Pin your team's agent API endpoint and model list in managed config, and block unknown LLM hosts
  • Agent logs and memory files are sensitive data; store them like you store credentials

Know where your agent's tokens actually go. We set up coding-agent rollouts with pinned endpoints, approved models, and logs that stay in your account. See how we build agent systems, or tell us which AI tools your developers run today.

Sources: CrowdStrike, BleepingComputer.

  • #claude-code
  • #ai-security
  • #coding-agents
  • #llm-proxy
  • #crowdstrike
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.