AI-Driven tool ARTEX used in attacks against South Korean Banks
AI-Driven tool ARTEX used in attacks against South Korean Banks

CrowdStrike analyzes open directories left by an attacker who used the ARTEX AI pentest tool and LLMs to breach South Korean financial firms.
CrowdStrike published a research on a campaign against South Korean financial organizations that ran from late September to early October 2026 and ended with stolen data. The attacker left their working notes where anyone could read them.
Open directories on servers controlled by the attacker exposed Claude Code session histories, ARTEX configuration files, and Claude memory files. Researchers could see how the operator worked, prompt by prompt. That is rare, and it makes this report particularly interesting.
“Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling.” reads the report published by CrowdStrike. “The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft.”
ARTEX is a recently released open-source tool from China that allows AI agents to run penetration tests on their own. The attacker combined it with large language models. CrowdStrike has not linked the activity to a specific group, but it has moderate confidence that the operator is Chinese-speaking and financially motivated, based on the tool used and the Chinese-language prompts.
Industry reports describe several South Korean financial organizations breached since late September. At one bank, the attacker reportedly got into a loan progress inquiry service used by financial brokers. At another, they compromised an employee mobile work-support system. Nobody has confirmed how many organizations were hit.
Investigators connected the dots through overlapping IP addresses and references to the string ARTEX in HTML files on a server the attacker reportedly controlled. One address, 38.244.50[.]120, hosted an ARTEX instance and an open directory. Inside sat a Claude Code markdown file with a Chinese-language pentesting prompt that told the model how to run its tests.
“The IP address 38.244.50[.]120 was associated with the activity described and hosted an ARTEX instance and open directory containing a Claude Code markdown document at http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md.” continues the report. “The markdown document contained a Chinese-language pentesting prompt that specified how the LLM should conduct pentesting activities.”
That file also pointed to a Hong Kong IP address, and that server held more open directories with session histories, configuration files and memory files. The files show the operator going after Korean financial targets with ARTEX and LLMs across those weeks, and the targets match the ones in industry reporting.
The sessions reveal a two-server setup. The Hong Kong address is the attacker’s main infrastructure, and 38.244.50[.]120 runs the ARTEX instance likely behind the Korean attacks. DeepSeek v4.1-flash served as the main model, with GLM-5.3 from Zhipu AI and Grok 4.6 added for extra sessions. The operator probably reached DeepSeek through a reseller, xcai[.]pro, and used nine proxy addresses that CrowdStrike lists in its report.
“Analysis of Claude Code sessions showed the threat actor also used the following proxy IP addresses during the ARTEX-related activity:
101.53.80[.]20205.214.59[.]31124.155.252[.]63154.201.79[.]24623.248.249[.]9023.158.220[.]98103.248.148[.]84203.160.133[.]172209.209.85[.]38
In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups.” reads the report.
Exfiltration was only the first step. The stolen data was already being prepared for sale.
In one session, the user asked Claude to write a security researcher résumé with bullet points describing the ARTEX results. The prompt also included personal details. The same Telegram username appeared in sessions involving a Telegram-based NFT gift marketplace and the targeting of what may have been a Chinese payment platform. CrowdStrike says the details likely belong to the operator, but it cannot confirm the link. Given that uncertainty, those details should not be included in a news article.
According to The Hacker News, ARTEX’s developer, Autumn-27, has since closed the source and stopped updates, saying the tool was built for learning and research and that the attacks have nothing to do with the project. Copies already in circulation don’t disappear with a license change.
CrowdStrike says this activity shows how AI tooling can let a financially motivated actor run several intrusions in a short time.
“The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft. This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.” concludes the report. “CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, ARTEX)
