Cybersecurity Research

AI-Assisted Hackers Breach South Korean Financial Firms Using Open-Source Pentesting Tool

CrowdStrike · 7 Oct 2026
Key Takeaway Tools built for legitimate security testing can be turned against you, so make sure externally facing services, such as partner portals and staff mobile systems, are patched, monitored and protected with strong access controls.

CrowdStrike Intelligence has identified infrastructure linked to a targeted campaign against South Korean financial organisations, which resulted in stolen data. The activity ran from late September to early October 2026. Open directories controlled by the attacker exposed Claude Code session histories, ARTEX configuration files and Claude memory files, giving researchers direct insight into how the attacker worked.

ARTEX is a recently released, open-source tool developed in China that uses agentic AI to carry out penetration testing. The attacker paired it with large language models alongside traditional offensive methods. The activity has not been attributed to a named group. CrowdStrike assesses with moderate confidence that the actor is likely a Chinese speaker and financially motivated, based on the use of ARTEX and Chinese-language prompts. One recovered document contained a Chinese-language pentesting prompt instructing the AI how to conduct its activities.

According to industry reports, several South Korean financial organisations suffered breaches from late September 2026. At one bank, attackers reportedly breached a loan progress inquiry service used by financial brokers. At another, they compromised an employee mobile work-support system. The number of affected organisations remains unconfirmed. Activity at multiple victims reportedly involved overlapping IP addresses, which may help defenders spot related intrusions.

AI ARTEX Financial Sector Data Breach Threat Intelligence
Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from CrowdStrike, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.