Authorities are stepping up efforts to identify the hackers behind an unprecedented series of artificial intelligence (AI)-assisted cyberattacks targeting Korea's major financial institutions, Thursday, as a global cybersecurity firm pointed to a possible suspect based in China. CrowdStrike said in a report released the previous day that the threat actor was likely a Chinese speaker and financially motivated. The firm assessed that the attacker may have been a Chinese-speaking individual, citing the use of ARTEX, a Chinese-developed autonomous penetration-testing tool and Chinese-language prompts observed during the attacks. In its report, CrowdStrike suggested that the attacker primarily used DeepSeek's V4.1-Flash as the large language model backend for ARTEX, while also using GLM-5.3 from Chinese AI company Zhipu AI and Grok 4.6 in separate Claude Code sessions. A key clue emerged from a Claude Code session in which the attacker asked the AI tool to draft a resume for a security researcher. The information entered into the session included an age of 26, an educational background at Sou