
CrowdStrike has linked a financially motivated cyber campaign against South Korean financial firms to a Chinese-developed autonomous penetration-testing platform called ARTEX, after investigators recovered the attackers’ operational files, AI prompts and coding-agent session histories from exposed infrastructure.
The activity ran from late September into early October 2026 and involved multiple large financial institutions. CrowdStrike said the operator used ARTEX with several large language models and Claude Code to automate reconnaissance, exploitation and data collection against externally exposed systems.
The security company has not publicly attributed the campaign to a known hacking group. It assessed with moderate confidence that the operator was probably Chinese-speaking and financially motivated, based partly on Chinese-language instructions and the use of ARTEX. That assessment does not establish the operator’s nationality or physical location.
CrowdStrike’s investigation was aided by files left accessible on attacker-controlled infrastructure. Among them were Claude Code session histories, Claude memory files and ARTEX configuration data. The material gave investigators visibility into how the operator instructed and used AI systems during the campaign.
One exposed server at 38.244.50.120 hosted an ARTEX instance. An exposed /.claude/CLAUDE.md file contained Chinese-language instructions directing the AI agent to perform penetration-testing tasks.
DeepSeek V4.1-Flash was identified as the primary large language model backend for the ARTEX deployment. CrowdStrike also identified GLM-5.3 and Grok 4.6 in related Claude Code sessions. The investigators said the operator likely accessed DeepSeek through xcai.pro, which they described as a likely LLM API proxy or reseller.
That setup made Claude Code part of a broader tooling chain rather than the sole system conducting the attacks. ARTEX provided the penetration-testing framework, while different AI models were used to support the operator’s activities.
CrowdStrike’s technical account details the infrastructure and AI artifacts recovered during the investigation.
The campaign did not require access to the core transaction systems of the affected banks. Instead, attackers targeted peripheral internet-facing applications and services that exposed financial or customer information.
At Shinhan Bank, the targeted system was a loan-progress inquiry service used by loan brokers. At KB Kookmin Bank, an employee mobile work-support system was among the systems targeted.
South Korean reporting said the Shinhan attack began at about 6:04 p.m. on September 28 and continued for roughly 30 hours. About 25,727 records were reportedly exposed. The affected data included personal and financial information such as names, contact details, annual income and loan limits.
Other institutions reported additional exposures. Yegaram Savings Bank reported information involving about 40,000 customers, while Welcome Savings Bank reported about 2,200 corporate records. Hana Bank reported 89 affected customers, KB Kookmin Bank reported 119, and Hyundai Capital reported information relating to 146 housing-loan agents. BNK Busan Bank also reported exposure involving 11 outsourced development employees.
South Korean reports also described attacks against other financial companies, including PFCT and the online investment platform MOUDA. Some related incidents remained under investigation, and authorities had not established that every reported case was necessarily conducted by the same operator.
At least nine South Korean banks were reported to have been targeted, although several organizations blocked suspicious activity before identifying a data leak.
The recovered AI session histories provided evidence of a financial motive. CrowdStrike found prompts in which the operator asked about places where stolen Korean data could be sold and sought information about Korean Telegram groups associated with data trading.
The activity suggests that the operator was using AI agents to support a conventional financially motivated intrusion operation rather than conducting a security test. CrowdStrike said the campaign involved actual data exfiltration.
Financial regulators also found evidence of infrastructure spread across multiple jurisdictions. By October 6, South Korea’s Financial Supervisory Service had identified 28 suspected attack IP addresses across 12 countries. CrowdStrike separately documented nine proxy IP addresses used during the campaign.
The proxy addresses included infrastructure associated with South Korea, the United States, Japan, Hong Kong, Singapore, Vietnam, Thailand and the United Kingdom. The use of those locations does not establish that the attacker was physically operating from any of them.
ARTEX is an open-source autonomous penetration-testing project maintained on GitHub under the account Autumn-27/ARTEX. The project describes itself as a system for automated security assessment and red-team operations.
Its documentation says the tool was intended for security research, learning and authorized testing rather than attacks against real-world systems. The project had also added controls for restricting targets, including rules intended to prevent testing of certain government domains.
ARTEX was released publicly in July 2026 and underwent rapid development during the following months. Its release history shows continued additions to its agent, task-management and testing capabilities shortly before the Korean attacks.
After the incidents emerged, the project’s developer said ARTEX would be moved to a closed-source model and that public releases and maintenance would stop, according to The Hacker News.
CrowdStrike also recovered an AI-assisted résumé session containing a possible operator profile. The material described a 26-year-old person identified as “YY,” with an educational background at South China University of Technology and a residence in Maoming, Guangdong.
CrowdStrike said those details likely belonged to the operator but could not establish that connection conclusively.
The identity was later disputed publicly. Korean media reported that a person associated with the relevant phone number and Telegram account denied being responsible for the attacks and gave conflicting details about his education and location. The associated Telegram account was later removed.
South Korean police established a dedicated investigation team and are tracing the attacker and the route used to compromise the financial systems. The investigation includes international cooperation.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.



