Threat

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

Page published · Page updated

Dossier

Earliest dated coverage: 9 Oct 2026 · First observed: 11 Oct 2026 · Latest dated coverage: 9 Oct 2026

Coverage timeline

discovered crowdstrike.com primary 9 Oct 2026securityweek.com

Single-source incident — one report is available.

Why it matters

The ARTEX campaign is a real, in-the-wild demonstration of adversaries chaining agentic AI pentest tooling with multiple LLM backends to carry out autonomous intrusions and data theft against financial targets, confirming the operational use of agentic AI in real attacks.

CrowdStrike Intelligence detailed a campaign in which an unattributed, likely Chinese-speaking and financially motivated threat actor used ARTEX, an open-source agentic penetration-testing tool, alongside LLMs (DeepSeek, GLM, Grok, Claude Code) to breach South Korean financial organizations and exfiltrate data in late September to early October 2026. The same SecurityWeek roundup also covers PoeLLM, malware that targets exposed AI services (LiteLLM, Ollama) and hides its C&C IP in a GitHub-hosted poem to grow a cryptomining botnet.

campaign

Summary

CrowdStrike Intelligence identified infrastructure tied to a targeted campaign against South Korean financial organizations that was active from late September to early October 2026 and resulted in exfiltrated data. The investigation surfaced Claude Code session histories, ARTEX configuration files, and Claude memory files in threat actor-controlled open directories.[0][11]

The operator leveraged ARTEX — a recently released open-source agentic penetration-testing tool developed in China — together with large language models to conduct the intrusions. CrowdStrike assesses with moderate confidence that the actor is a Chinese speaker and financially motivated, based on use of the Chinese-developed tooling and observed Chinese-language prompts; the activity is not attributed to a named adversary.[11]

The campaign reached public attention amid a broader South Korean government probe, with President Lee Jae Myung stating that AI appears to have been used in some of the recent bank-targeting hacking incidents, which exposed customers' personal information. Police have reportedly opened a full-scale investigation.[0]

Attack chain

  1. Initial Access: The threat actor reportedly breached a loan progress inquiry service used by financial brokers at one bank and compromised an employee mobile work-support system at another; activity across multiple organizations purportedly involved overlapping IP addresses.[11]
  2. AI-Driven Tooling / Operations: The actor ran an ARTEX agentic pentesting instance on 38.244.50.120 driven by a Chinese-language pentesting prompt stored in a Claude Code CLAUDE.md file, using DeepSeek v4.1-flash as the primary LLM backend and supplementing with GLM-5.3 and Grok 4.6, with a Hong Kong-based IP serving as primary attacker-controlled infrastructure.[11]
  3. Exfiltration: The campaign against South Korean financial organizations resulted in exfiltrated data, including a breach of customers' personal information.[0][11]

Disclosure timeline

DateEvent
Late September 2026Several South Korean financial organizations began experiencing data breaches; the campaign infrastructure was active from late September to early October 2026.[0][11]
October 07, 2026CrowdStrike published its analysis linking the campaign to ARTEX and LLM-based tooling and profiling the likely Chinese-speaking, financially motivated actor.[11]
This week (as reported)South Korean President Lee Jae Myung said AI appears to have been used in some of the bank attacks, and police reportedly launched a full-scale investigation.[0]

How it works

Rather than a software vulnerability, the operation's mechanics center on agentic AI tradecraft: an ARTEX instance hosted on 38.244.50.120 was driven by a Chinese-language pentesting prompt in a Claude Code CLAUDE.md file instructing the LLM how to conduct pentesting activities, using DeepSeek v4.1-flash as the primary backend and GLM-5.3 and Grok 4.6 for additional sessions, with DeepSeek likely reached via the proxy/reseller xcai.pro.[11]

Indicators of Compromise

TypeIndicatorContext
ip38.244.50.120Hosted an ARTEX instance and an open directory containing a Claude Code CLAUDE.md markdown document; assessed as the ARTEX instance likely responsible for the Korean attacks.[11]
domainxcai.proLikely LLM API proxy/reseller through which the threat actor likely accessed DeepSeek.[11]
otherARTEXThe string 'ARTEX' was observed in HTML files on a reportedly threat actor-controlled server, indicating use of the ARTEX agentic pentesting tool.[11]

Key takeaways

  • Threat actors are operationalizing agentic AI pentesting tools such as the Chinese-developed ARTEX alongside multiple commercial LLM backends (DeepSeek, GLM, Grok) to conduct real-world financially motivated intrusions.[11]
  • Operational security lapses — threat actor-controlled open directories exposing Claude Code session histories, ARTEX configs, and Claude memory files — gave defenders direct insight into the actor's methodology and infrastructure.[0][11]

Defensive actions

  • Block and hunt for connections to the ARTEX host 38.244.50.120 and the suspected LLM proxy xcai.pro.: These are the identified attacker-controlled infrastructure endpoints associated with the campaign against South Korean financial organizations.[11]
  • Review access to broker-facing loan progress inquiry services and employee mobile work-support systems for signs of compromise.: These specific services were reportedly the breach points at affected banks in this campaign.[11]