Key Takeaways

  • Intelligence analysts found evidence that a likely Chinese-speaking, financially motivated attacker used ARTEX and large language models during breaches of South Korean financial organizations.
  • Exposed session histories and configuration files show an AI-assisted workflow, but they do not prove the intrusions operated without human direction.
  • The campaign highlights risks in externally accessible banking systems, particularly mobile work tools, loan-recruitment services, and sales-support applications.

CrowdStrike Intelligence has linked a series of data breaches at South Korean financial organizations to infrastructure running ARTEX, an open-source agentic penetration-testing system developed in China. The campaign operated from late September to early October 2026 and resulted in data exfiltration.

The attacker has not been attributed to a named hacking group. CrowdStrike assesses with moderate confidence that the person behind the activity was likely a Chinese speaker and financially motivated, based partly on Chinese-language prompts and the use of ARTEX. Those clues indicate language and probable motivation, not nationality or state sponsorship.

According to industry reports, multiple South Korean financial organizations experienced data breaches during the campaign, though the exact number of affected institutions remains unconfirmed.

The most consequential evidence was not simply the presence of an AI security tool. Analysts discovered exposed Claude Code session histories, ARTEX configuration files, and Claude memory files in attacker-controlled open directories. Together, the records offered a rare view into how an attacker incorporated large language models into an operational intrusion workflow.

Analysis identified a two-server setup. A Hong Kong-based system appeared to function as the attacker's primary infrastructure, while 38.244.50[.]120 hosted the ARTEX instance associated with the South Korean activity. Multiple proxy addresses were also used, consistent with an effort to distribute or obscure the campaign's network traffic.

The ARTEX deployment was used alongside large language models. The threat actor utilized Claude Code, as evidenced by an exposed markdown document containing a Chinese-language pentesting prompt specifying how the AI should conduct its activities. The flexibility of agentic tooling allows operators to incorporate artificial intelligence seamlessly into offensive operations.

Still, calling this an autonomous AI attack would go beyond the available evidence. The exposed files show that the attacker wrote prompts, configured systems, selected infrastructure, and interacted with model outputs. ARTEX appears to have helped coordinate or accelerate parts of the work. It did not, based on the evidence disclosed so far, independently choose targets and execute the entire campaign without human involvement.

Exaggerated claims about autonomous hacking can distract security leaders from the more immediate risk: relatively accessible AI tooling may allow an individual operator to investigate vulnerabilities, manage tasks, and work across several targets faster than before.

The initial entry points also look familiar. The incidents were connected to weaknesses in externally accessible services, specifically a loan progress inquiry service used by financial brokers at one bank, and an employee mobile work-support system at another. AI may have increased the attacker's tempo, but ordinary attack-surface weaknesses still provided the opportunity.

The use of the Chinese-developed tool ARTEX and observed Chinese-language prompts support the assessment of financial motivation, although the exact monetization strategy remains unclear. The combination of traditional offensive capabilities with agentic AI indicates an evolution in adversarial tradecraft aimed at accelerating attacks for financial gain.

For banks, the response should extend beyond blocking the disclosed infrastructure. Indicators such as proxy addresses can change quickly. More durable measures include reviewing internet-facing business applications, restricting administrative access, examining mobile workforce systems, and monitoring for unusual enumeration or automated testing across related services.

The NIST Cybersecurity Framework 2.0 offers a useful structure for identifying exposed assets, protecting access, detecting abnormal behavior, responding to intrusions, and recovering afterward. NIST's AI Risk Management Framework can also help organizations evaluate how AI changes both offensive capability and defensive governance.

This campaign does not show that human hackers have been replaced. It shows something more practical, and perhaps more pressing: AI-assisted offensive tooling is moving into real financial-sector operations, compressing timelines while exploiting security gaps that defenders already know how to address.