Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance CrowdStrike Intelligence identified a financially motivated, likely Chinese-speaking threat actor that used the open-source agentic pentesting tool ARTEX alongside large language models to breach South Korean financial organizations between late September and early October 2026, exfiltrating data. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files showing a two-server architecture in which the Hong Kong-based IP served as primary infrastructure and IP 38.244.50[.]120 hosted the ARTEX instance used in the Korean attacks. The ARTEX instance ran DeepSeek v4.1-flash as its primary LLM backend, supplemented by GLM-5.3 (Zhipu AI) and Grok 4.6, with DeepSeek likely accessed through the LLM API proxy/reseller xcai[.]pro; the number of affected organizations remains unconfirmed. CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026. Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor's operational methodology and tooling. The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution CrowdStrike has observed in adversarial tradecraft. In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing pentesting tool developed in China, alongside large language models LLMs . CrowdStrike’s intelligence collection capabilities enable close monitoring of such developments in adversarial tradecraft. While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated. This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts. Details According to industry reports,