Threat Intelligence

AI Pentesting Tool ARTEX Turned Against South Korean Financial Firms in Data Theft Campaign

The Hacker News · 9 Oct 2026
Key Takeaway Assume attackers can now use AI tools to probe your systems quickly, so regularly patch internet-facing systems, review what is exposed online, and monitor for unusual data transfers.

CrowdStrike Intelligence has detailed a targeted campaign against South Korean financial organisations that ran from late September to early October 2026 and resulted in data theft. The attacker used ARTEX, a recently released open-source, AI-driven penetration testing tool developed in China, together with large language models (LLMs).

CrowdStrike found the campaign after spotting open directories on a Hong Kong-based IP address. These exposed Claude Code session histories, Claude memory files and ARTEX configuration files. ARTEX is a multi-agent system that runs penetration tests autonomously. In this case it mainly used DeepSeek as its language model, supported by Z.ai's GLM and SpaceXAI's Grok. The operator is suspected to have reached DeepSeek through an LLM API reseller. The sessions also showed the operator asking Claude where Korean data breach information is typically sold and for help finding Korean Telegram data sales groups.

The campaign has not been linked to any known threat actor, though the evidence points to a suspected Chinese-speaking operator motivated by money. One prompt referenced a Telegram username, but CrowdStrike said the available information cannot definitively tie those details to the attacker. ARTEX's developer, Autumn-27, has since taken the tool closed source and said the attacks had nothing to do with them and go against the tool's purpose.

AI security data theft penetration testing financial sector CrowdStrike
Regulated in financial services? APRA CPS 220, 230 and 234, in plain language ->

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.