Threat

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

Page published · Page updated

Dossier

Earliest dated coverage: 10 Oct 2026 · First observed: 10 Oct 2026 · Latest dated coverage: 10 Oct 2026

Coverage timeline

discovered crowdstrike.com primary 10 Oct 2026bleepingcomputer.com

Single-source incident — one report is available.

Why it matters

The ARTEX-and-Claude campaign against South Korean banks is a confirmed real-world intrusion where agentic AI tooling autonomously drove the offensive operations against critical financial systems, marking an escalation defenders must prepare for.

A Chinese-speaking, financially-motivated threat actor used the ARTEX AI agentic penetration-testing suite alongside Claude Code agents and multiple LLM backends (DeepSeek v4.1-flash, GLM-5.3, Grok 4.6) to breach South Korean banks including Shinhan, KB Kookmin, and Hana, exfiltrating customer personal and credit-card data and causing system outages. CrowdStrike confirmed ARTEX use after analyzing attacker-controlled open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files across a two-server infrastructure.

campaign

Summary

CrowdStrike Intelligence identified a targeted campaign against South Korean financial organizations, active from late September to early October 2026, that resulted in exfiltrated data. The threat actor leveraged ARTEX — a recently released Chinese-developed open-source agentic penetration testing tool — alongside Claude Code agents and multiple large language models.[1][2]

Analysis of threat actor-controlled open directories exposed Claude Code session histories, ARTEX configuration files, and Claude memory files, giving direct insight into the operator's methodology and tooling. Targeted banks reportedly included Shinhan Bank, KB Kookmin Bank, and Hana Bank, with exposure of client personal and credit card data and some system outages, prompting an emergency South Korean government response.[1][2]

The activity has not been attributed to a named adversary, but CrowdStrike assesses with moderate confidence that the actor is a Chinese speaker and financially motivated, based on the Chinese-developed tooling and Chinese-language prompts. Operational security lapses — including reuse of the same AI tools to draft a résumé — exposed personal details that may point to the individual, though they are not reliable enough to confirm identity.[1][2]

Attack chain

  1. Tooling and infrastructure setup: The threat actor deployed ARTEX, a Chinese-developed open-source agentic pentesting tool, across a two-server architecture: a Hong Kong-based IP as primary attacker infrastructure and 38.244.50[.]120 hosting the ARTEX instance. ARTEX used DeepSeek v4.1-flash as its primary LLM backend, supplemented with GLM-5.3 and Grok 4.6, with DeepSeek likely accessed through the proxy/reseller xcai[.]pro.[2]
  2. AI-driven reconnaissance and exploitation: The actor used ARTEX and LLMs via Claude Code sessions to conduct pentesting activity against South Korean financial organizations, guided by a Chinese-language pentesting prompt stored in a CLAUDE.md file specifying how the LLM should perform the attacks.[2]
  3. Breach of banking systems: At one bank the actor reportedly breached a loan progress inquiry service used by financial brokers; at another, an employee mobile work-support system was compromised, with multiple organizations' activity involving overlapping IP addresses.[2]
  4. Data exfiltration and outages: The campaign exposed clients' personal data and credit card information and caused system outages at some banks, exfiltrating data from affected organizations.[1][2]
  5. Post-exfiltration monetization planning: Records show the actor had no concrete plan to monetize the stolen bank data and asked Claude to propose Korea-focused Telegram data-sales groups.[1]

Disclosure timeline

DateEvent
Late September 2026Campaign begins; several South Korean financial organizations experience data breaches.[2]
Late September to early October 2026Threat actor conducts extensive activity against South Korean financial organizations using ARTEX and LLMs.[2]
October 07, 2026CrowdStrike publishes analysis of the ARTEX-based campaign and its infrastructure.[2]
October 10, 2026BleepingComputer reports on the attacks, naming affected banks and the emergency South Korean government response; ARTEX developer makes the project closed-source.[1]

Indicators of Compromise

TypeIndicatorContext
ip38.244.50.120IP address hosting the ARTEX instance likely responsible for the described Korean attacks; served an open directory with a Claude Code markdown document at port 18899.[2]
domainxcai.proLikely LLM API proxy/reseller through which the threat actor accessed DeepSeek.[1][2]

Key takeaways

  • The campaign demonstrates adversarial use of agentic AI tooling (ARTEX plus Claude Code and multiple LLMs) alongside traditional offensive techniques, reflecting an evolution in offensive tradecraft against the financial sector.[1][2]
  • Operator OPSEC failures — open directories exposing session histories, configuration and memory files, plus reuse of the same AI tools to draft a résumé — gave investigators direct insight into methodology and possible identity, though attribution to a named actor remains unconfirmed.[1][2]

Defensive actions

  • Block and hunt for the identified attacker infrastructure, including 38.244.50[.]120 and the xcai[.]pro proxy.: These are the grounded infrastructure indicators tied to the ARTEX instance and LLM access used in the campaign.[1][2]
  • Implement immediate security measures for critical IT systems, particularly loan inquiry and employee mobile work-support services.: The South Korean government convened an emergency meeting and called for immediate measures after breaches of these specific banking service types.[1][2]