Threat
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
First reported crowdstrike.com
Page published
Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026
Coverage timeline
Single-source incident — one report is available.
Why it matters
The ARTEX campaign demonstrates adversaries operationalizing agentic AI pentesting tooling and multiple LLM backends to autonomously breach and exfiltrate data from real financial institutions, marking a tangible escalation in AI-driven offensive tradecraft defenders must detect.
CrowdStrike Intelligence disclosed a targeted campaign against South Korean financial organizations that used ARTEX, a recently released open-source agentic penetration testing tool developed in China, alongside LLMs including DeepSeek, GLM-5.3, and Grok to conduct attacks and exfiltrate data between late September and early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, revealing a two-server architecture and Chinese-language pentesting prompts; the unnamed actor is assessed as a likely Chinese-speaking, financially motivated operator.