Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

October 07, 2026

• • Threat Hunting & Intel

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.

The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft. In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs). CrowdStrike’s intelligence collection capabilities enable close monitoring of such developments in adversarial tradecraft.

While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated. This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.

Details

According to industry reports,1 beginning in late September 2026, several South Korean financial organizations experienced data breaches. At one affected bank, the threat actor reportedly breached a loan progress inquiry service used by financial brokers. At another bank, the threat actor compromised an employee mobile work–support system. As of this writing, the number of organizations affected remains unconfirmed.

Activity at multiple organizations purportedly involved overlapping IP addresses. Reporting also suggested the attacker used ARTEX based on references to the string ARTEX in HTML files observed on a reportedly threat actor-controlled server.

ARTEX Infrastructure Analysis

The IP address 38.244.50[.]120 was associated with the activity described and hosted an ARTEX instance and open directory containing a Claude Code markdown document at http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md. The markdown document contained a Chinese-language pentesting prompt that specified how the LLM should conduct pentesting activities. A threat actor-controlled Hong Kong–based IP address also appeared in the document. 

Analysis of the Hong Kong-based IP address identified additional open directories that contained Claude Code session histories, ARTEX configuration files, and Claude memory files. These files indicate that from late September 2026 to early October 2026, the threat actor targeted South Korean financial organizations with extensive activity leveraging ARTEX and LLMs. Targeted organizations overlap with those identified in industry reporting. 

The Claude Code sessions reveal a two-server architecture: The Hong Kong-based IP address serves as the primary attacker-controlled infrastructure, and the IP address 38.244.50[.]120 hosts the ARTEX instance likely responsible for the described Korean attacks. The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions. The threat actor likely accessed DeepSeek via the likely LLM API proxy/reseller xcai[.]pro.

Analysis of Claude Code sessions showed the threat actor also used the following proxy IP addresses during the ARTEX-related activity:

  • 101.53.80[.]20
  • 205.214.59[.]31
  • 124.155.252[.]63
  • 154.201.79[.]246
  • 23.248.249[.]90
  • 23.158.220[.]98
  • 103.248.148[.]84
  • 203.160.133[.]172
  • 209.209.85[.]38

In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups.

Possible Threat Actor Details

In one Claude Code session, the user asked Claude to create a security researcher résumé that specifically included bullet points conveying the results of the ARTEX-related activity. The prompt included the following personal details:

  • Name: YY
  • Phone: 17820191556
  • Telegram: @YY520CN
  • Age: 26 (though the attacker initially provided the date of birth 2007-09-22)
  • Education: South China University of Technology
  • Location: Maoming, Guangdong, China

Claude Code sessions conducting vulnerability research on a Telegram-based NFT gift marketplace also used the Telegram username YY520CN. An unknown threat actor also employed this username to target a possible Chinese payment platform. While the personal details included in the prompt likely belong to the threat actor who conducted the ARTEX-related activity, currently available information cannot definitively associate these details with the threat actor.

Assessment

The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft. This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities. 

IOCs

This table details the IOCs related to the information provided in this report.

Table 1. IOCs
IOCDescription
101.53.80[.]20Proxy IP address
205.214.59[.]31Proxy IP address
124.155.252[.]63Proxy IP address
154.201.79[.]246Proxy IP address
23.248.249[.]90Proxy IP address
23.158.220[.]98Proxy IP address
103.248.148[.]84Proxy IP address
203.160.133[.]172Proxy IP address
209.209.85[.]38Proxy IP address
38.244.50[.]120Threat actor-controlled IP address

MITRE ATT&CK

This table details the tactics and techniques described in this report. 

Table 2. MITRE ATT&CK
TacticTechniqueObservables
Resource DevelopmentT1583.003 - Acquire Infrastructure: Virtual Private ServerThe threat actor acquires infrastructure at multiple IP addresses to establish command-and-control operations.
T1588.007 - Obtain Capabilities: Artificial IntelligenceThe threat actor obtains and deploys ARTEX, an open-source Chinese-developed agentic penetration testing tool, to conduct attacks against South Korean financial sector organizations.
Command and ControlT1090 - ProxyThe threat actor used multiple proxy IP addresses during the ARTEX-related activity.

1 https[:]//www.khan[.]co[.]kr/en/article/202610042320007


CrowdStrike Falcon Platform
Ready to protect your business?

Try CrowdStrike free today

Subscribe

Sign up now to receive the latest notifications and updates from CrowdStrike

See CrowdStrike Falcon in action