# Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool to Target South Korean Financial Organizations

> CrowdStrike reports an unattributed, likely Chinese-speaking, financially motivated actor using ARTEX, a recently released open-source agentic penetration testing tool developed in China, against multiple South Korean financial organizations from late September to early October 2026. Exposed open directories held Claude Code session histories, ARTEX configuration files and Claude memory files that reveal the LLM-assisted workflow.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3008
- **ID:** TL-2026-3008
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CrowdStrike Intelligence assesses with moderate confidence that a likely Chinese-speaking, financially motivated actor, not attributed to any named adversary, used ARTEX (an open-source agentic penetration testing console developed in China) against multiple South Korean financial organizations between late September and early October 2026. CrowdStrike identified a bank's loan progress inquiry service (used by financial brokers) and another bank's employee mobile work-support system as targets; the total number of affected organizations is unconfirmed.

An exposed open directory on the actor's ARTEX host 38.244.50.120 (port 18899, path /.claude/CLAUDE.md) held Chinese-language pentesting prompts, ARTEX configuration files, Claude Code session histories and Claude memory files, and referenced Hong Kong-based attacker infrastructure, including a Hong Kong IP. The material shows an LLM-assisted workflow in which the operator also asked an LLM to identify Korean data sales channels and Telegram groups and how threat actors monetize stolen data. LLM backends observed were DeepSeek v4.1-flash (likely reached through the xcai.pro API proxy/reseller), GLM-5.3 and Grok 4.6, alongside Claude Code. Nine additional proxy IPs were used to obscure operations.

Korean press reporting corroborates the victimology. Shinhan Bank's 'M Shinhan' mobile portal for loan officers (about 25,000 customers affected, including 66 resident registration numbers and 97 CI values, names, phone numbers, annual income and loan limits) and KB Kookmin Bank's employee mobile work-support system (119 customers) reported incidents to the FSS on 30 September 2026. Reports also cite Hana Bank (89 customers) and BNK Financial (11 external staff) and say the same external hacking AI agent was suspected. Press analysts described the method as credential stuffing and AI-driven random value injection against non-core platforms, and a security expert reported ARTEX's 'autonomous penetration testing console' banner on compromised servers. The press-reported technical details are secondary sourcing and are not confirmed by CrowdStrike's report. No CVEs are cited.

CrowdStrike assesses that adversaries will likely continue to experiment with AI tooling to enhance operational tempo and capabilities.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1583.003 Virtual Private Server
- T1588.007 Artificial Intelligence
- T1588.002 Tool
- T1190 Exploit Public-Facing Application
- T1078 Valid Accounts
- T1110.004 Credential Stuffing
- T1090 Proxy

## Sources

- [Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)
- [신한 이어 국민도 뚫렸다…"AI 침투하면 속수무책" 은행 보안 '비상' (Money Today)](https://www.mt.co.kr/article/2026100216055965103)
- [하루 만에 또…신한 이어 국민·하나도 고객 정보 털렸다 (SBS Biz)](https://biz.sbs.co.kr/amp/article/20000338176)
- [Shinhan Bank customer data breach via M Shinhan (Hankyung)](https://www.hankyung.com/article/202610018778Y)
- [YTN report on Korean bank AI-agent data breaches](https://www.ytn.co.kr/_ln/0102_202610022019246878)
- [Tracking CyberStrikeAI Usage (Team Cymru) - related Chinese AI-native pentest tool](https://www.team-cymru.com/post/tracking-cyberstrikeai-usage)
- [CSA research note: UAT-10147 AI agentic attack scaling - related agentic attack research](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/08/CSA_research_note_uat10147_ai_agentic_attack_scaling_20260825-csa-styled.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3008
