AI-Assisted Hackers Breach South Korean Financial Firms Using Open-Source Pentesting Tool
CrowdStrike Intelligence has identified infrastructure linked to a targeted campaign against South Korean financial organisations, which resulted in stolen data. The activity ran from late September to early October 2026. Open directories controlled by the attacker exposed Claude Code session histories, ARTEX configuration files and Claude memory files, giving researchers direct insight into how the attacker worked.
ARTEX is a recently released, open-source tool developed in China that uses agentic AI to carry out penetration testing. The attacker paired it with large language models alongside traditional offensive methods. The activity has not been attributed to a named group. CrowdStrike assesses with moderate confidence that the actor is likely a Chinese speaker and financially motivated, based on the use of ARTEX and Chinese-language prompts. One recovered document contained a Chinese-language pentesting prompt instructing the AI how to conduct its activities.
According to industry reports, several South Korean financial organisations suffered breaches from late September 2026. At one bank, attackers reportedly breached a loan progress inquiry service used by financial brokers. At another, they compromised an employee mobile work-support system. The number of affected organisations remains unconfirmed. Activity at multiple victims reportedly involved overlapping IP addresses, which may help defenders spot related intrusions.