Threat

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

Page published

Earliest dated coverage: 8 Oct 2026 · First observed: 8 Oct 2026 · Latest dated coverage: 8 Oct 2026

Coverage timeline

discovered crowdstrike.com primary 8 Oct 2026thehackernews.com

Single-source incident — one report is available.

Why it matters

The ARTEX campaign demonstrates adversaries operationalizing agentic AI pentesting tooling and multiple LLM backends to autonomously breach and exfiltrate data from real financial institutions, marking a tangible escalation in AI-driven offensive tradecraft defenders must detect.

CrowdStrike Intelligence disclosed a targeted campaign against South Korean financial organizations that used ARTEX, a recently released open-source agentic penetration testing tool developed in China, alongside LLMs including DeepSeek, GLM-5.3, and Grok to conduct attacks and exfiltrate data between late September and early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, revealing a two-server architecture and Chinese-language pentesting prompts; the unnamed actor is assessed as a likely Chinese-speaking, financially motivated operator.