{"slug": "unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance", "title": "Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance", "summary": "CrowdStrike Intelligence identified a financially motivated, likely Chinese-speaking threat actor that used the open-source agentic pentesting tool ARTEX alongside large language models to breach South Korean financial organizations between late September and early October 2026, exfiltrating data. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files showing a two-server architecture in which the Hong Kong-based IP served as primary infrastructure and IP 38.244.50[.]120 hosted the ARTEX instance used in the Korean attacks. The ARTEX instance ran DeepSeek v4.1-flash as its primary LLM backend, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6, with DeepSeek likely accessed through the LLM API proxy/reseller xcai[.]pro; the number of affected organizations remains unconfirmed.", "body_md": "CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling.\n\nThe use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft. In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs). CrowdStrike’s intelligence collection capabilities enable close monitoring of such developments in adversarial tradecraft.\n\nWhile this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated. This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.\n\n## Details\n\nAccording to industry reports,<sup>1</sup> beginning in late September 2026, several South Korean financial organizations experienced data breaches. At one affected bank, the threat actor reportedly breached a loan progress inquiry service used by financial brokers. At another bank, the threat actor compromised an employee mobile work–support system. As of this writing, the number of organizations affected remains unconfirmed.\n\nActivity at multiple organizations purportedly involved overlapping IP addresses. Reporting also suggested the attacker used ARTEX based on references to the string `ARTEX` in HTML files observed on a reportedly threat actor-controlled server.\n\n### ARTEX Infrastructure Analysis\n\nThe IP address `38.244.50[.]120` was associated with the activity described and hosted an ARTEX instance and open directory containing a Claude Code markdown document at `http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md`. The markdown document contained a Chinese-language pentesting prompt that specified how the LLM should conduct pentesting activities. A threat actor-controlled Hong Kong–based IP address also appeared in the document. \n\nAnalysis of the Hong Kong-based IP address identified additional open directories that contained Claude Code session histories, ARTEX configuration files, and Claude memory files. These files indicate that from late September 2026 to early October 2026, the threat actor targeted South Korean financial organizations with extensive activity leveraging ARTEX and LLMs. Targeted organizations overlap with those identified in industry reporting.\n\nThe Claude Code sessions reveal a two-server architecture: The Hong Kong-based IP address serves as the primary attacker-controlled infrastructure, and the IP address `38.244.50[.]120` hosts the ARTEX instance likely responsible for the described Korean attacks. The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions. The threat actor likely accessed DeepSeek via the likely LLM API proxy/reseller `xcai[.]pro`.\n\nAnalysis of Claude Code sessions showed the threat actor also used the following proxy IP addresses during the ARTEX-related activity:\n\n- `101.53.80[.]20`\n- `205.214.59[.]31`\n- `124.155.252[.]63`\n- `154.201.79[.]246`\n- `23.248.249[.]90`\n- `23.158.220[.]98`\n- `103.248.148[.]84`\n- `203.160.133[.]172`\n- `209.209.85[.]38`\n\nIn addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups.\n\n### Possible Threat Actor Details\n\nIn one Claude Code session, the user asked Claude to create a security researcher résumé that specifically included bullet points conveying the results of the ARTEX-related activity. The prompt included the following personal details:\n\n- Name: `YY`\n- Phone: `17820191556`\n- Telegram: `@YY520CN`\n- Age: `26` (though the attacker initially provided the date of birth`2007-09-22` )\n- Education: `South China University of Technology`\n- Location: `Maoming, Guangdong, China`\n\nClaude Code sessions conducting vulnerability research on a Telegram-based NFT gift marketplace also used the Telegram username YY520CN. An unknown threat actor also employed this username to target a possible Chinese payment platform. While the personal details included in the prompt likely belong to the threat actor who conducted the ARTEX-related activity, currently available information cannot definitively associate these details with the threat actor.\n\n## Assessment\n\nThe use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft. This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span. CrowdStrike Intelligence assesses that adversaries will likely continue to experiment with implementing AI tooling in their operations to enhance their operational tempo and capabilities.\n\n### IOCs\n\nThis table details the IOCs related to the information provided in this report.\n\n| Table 1. IOCs |  | \n|---|---|\n| IOC | Description | \n| `101.53.80[.]20` | Proxy IP address | \n| `205.214.59[.]31` | Proxy IP address | \n| `124.155.252[.]63` | Proxy IP address | \n| `154.201.79[.]246` | Proxy IP address | \n| `23.248.249[.]90` | Proxy IP address | \n| `23.158.220[.]98` | Proxy IP address | \n| `103.248.148[.]84` | Proxy IP address | \n| `203.160.133[.]172` | Proxy IP address | \n| `209.209.85[.]38` | Proxy IP address | \n| `38.244.50[.]120` | Threat actor-controlled IP address | \n\n### MITRE ATT&CK\n\nThis table details the tactics and techniques described in this report.\n\n| Table 2. MITRE ATT&CK |  |  | \n|---|---|---|\n| Tactic | Technique | Observables | \n| Resource Development | T1583.003 - Acquire Infrastructure: Virtual Private Server | The threat actor acquires infrastructure at multiple IP addresses to establish command-and-control operations. | \n|  | T1588.007 - Obtain Capabilities: Artificial Intelligence | The threat actor obtains and deploys ARTEX, an open-source Chinese-developed agentic penetration testing tool, to conduct attacks against South Korean financial sector organizations. | \n| Command and Control | T1090 - Proxy | The threat actor used multiple proxy IP addresses during the ARTEX-related activity. | \n\n<sup>1</sup> https[:]//www.khan[.]co[.]kr/en/article/202610042320007", "url": "https://wpnews.pro/news/unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance", "canonical_source": "https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/", "published_at": "2026-10-07 22:16:23.120419+00:00", "updated_at": "2026-10-07 22:16:25.414455+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "artificial-intelligence", "large-language-models"], "entities": ["CrowdStrike Intelligence", "ARTEX", "Claude Code", "DeepSeek v4.1-flash", "GLM-5.3", "Zhipu AI", "Grok 4.6", "xcai[.]pro"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance", "markdown": "https://wpnews.pro/news/unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance.md", "text": "https://wpnews.pro/news/unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance.txt", "jsonld": "https://wpnews.pro/news/unknown-threat-actor-uses-ai-driven-artex-to-target-south-korean-finance.jsonld"}}