Threat reportThreat IntelligenceTL-2026-3137

AI-assisted data-theft campaign against South Korean banks: CrowdStrike finds ARTEX agentic pentest tool, Claude Code session histories and Claude memory files on attacker infrastructure

highACTIVE

AI-assisted data-theft campaign against South Korean banks (TL-2026-3137) is a high-severity tracked intrusion set, first published 2026-10-09. It has no confirmed attribution, affects South Korean financial sector Internet-facing banking services (loan, maps to 5 MITRE ATT&CK techniques (T1090, T1190, T1583.003), and is covered by 9 detection rules and 20 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-3137

Threat ID
TL-2026-3137
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
south korea
Detection rules
9
Indicators of compromise
20

Malware and tooling in AI-assisted data-theft campaign against South Korean banks

Malware and tooling: ARTEX, Claude Code, DeepSeek v4.1-flash, GLM-5.3, Grok 4.6

How AI-assisted data-theft campaign against South Korean banks works

From late September to early October 2026 an unattributed, likely Chinese-speaking, financially motivated actor used the China-developed open-source agentic pentesting framework ARTEX, backed by LLMs, plus Claude Code to breach South Korean financial organizations and exfiltrate customer data. CrowdStrike assesses attribution with moderate confidence; South Korean police have opened a full investigation after President Lee Jae Myung said signs pointed to AI use.

CrowdStrike Intelligence identified infrastructure tied to a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. Analysis of threat-actor-controlled open directories exposed Claude Code session histories, ARTEX configuration files and Claude memory files (including a /.claude/CLAUDE.md file), giving direct insight into the operator's methodology. The campaign was active from late September to early October 2026. CrowdStrike published its report on 7-8 October 2026 (sources differ on the exact day).

ARTEX is described as a recently released open-source, LLM multi-agent autonomous penetration-testing framework developed in China by Autumn-27. The ARTEX instance believed responsible for the Korean intrusions was hosted at 38.244.50.120 and used DeepSeek v4.1-flash as its primary LLM backend. The operator supplemented it with GLM-5.3 (Zhipu AI) and Grok 4.6 in additional Claude Code sessions. A Hong Kong-based IP served as the primary attacker-controlled infrastructure, which makes a two-server architecture. The domain xcai.pro is assessed as an LLM API proxy/reseller used to reach DeepSeek. Nine additional proxy IPs were used for operational security. CrowdStrike also lists VPS acquisition for C2 and acquisition of ARTEX as resource-development activity.

Reported operational activity includes breaching a loan progress inquiry service at one bank and compromising an employee mobile work-support system at another organization. The Claude Code sessions show the operator asking where to sell the stolen Korean data and for help finding Korean Telegram groups that trade breach data. CrowdStrike's public reporting identifies no CVEs and does not detail the initial-access vector or exfiltration method; third-party write-ups only generically describe automated scanning and exploitation of exposed web applications and services.

Media reports name Shinhan Bank (about 25,000 customers, confirmed 30 September), KB Kookmin Bank (119 customers, disclosed 2 October), Hana Bank (89 customers), BNK (11 outsourced workers) and Yegaram Savings Bank, with Taipei Times reporting at least nine banks targeted. Exposed data included names, phone numbers, annual income, calculated loan limits and 66 resident registration numbers. Counts come from press reports and differ between outlets. South Korea's Financial Services Commission warned of follow-on phishing and loan scams using the exposed data. The ARTEX developer subsequently closed the source and announced no further releases or maintenance, stating that abuse violates the tool's original purpose.

CrowdStrike assesses with moderate confidence that the actor is a financially motivated Chinese speaker, based on use of the Chinese-developed ARTEX tool and Chinese-language prompts. Reporting also cites unverified self-identifying details in a prompt, and these are deliberately not reproduced here. CrowdStrike SVP Adam Meyers noted the campaign let one human target many customers in a very short period using AI. The Chinese Foreign Ministry said China opposes hacking activity. Anthropic and the Korean police did not respond to press requests; one outlet notes Anthropic has detection and account-banning processes for Claude misuse.

MITRE ATT&CK techniques used in TL-2026-3137

Command and Control

T1090 Proxy

Initial Access

T1190 Exploit Public-Facing Application

Resource Development

T1583.003 Acquire Infrastructure: Virtual Private Server; T1588.007 Obtain Capabilities: Artificial Intelligence

Reconnaissance

T1595 Active Scanning

Affected products and versions in AI-assisted data-theft campaign against South Korean banks

  • South Korean financial sector — Internet-facing banking services (loan progress inquiry service, employee mobile work-support system)
    Vulnerable versions: Not specified in public reporting

Remediation for AI-assisted data-theft campaign against South Korean banks

Patches

  • No CVEs identified in public reporting; apply vendor patches to all internet-facing banking applications

Immediate actions

  • Block the network IOCs (38.244.50.120, the nine proxy IPs and xcai.pro) at perimeter and egress
  • Hunt web, API and proxy logs for automated scanning and exploitation of loan-inquiry and employee mobile work-support applications
  • Reset credentials and review access for any customer-data stores exposed through internet-facing services
  • Alert customers to follow-on phishing and loan scams using the exposed data

Workarounds

  • Restrict exposure of loan-inquiry and mobile work-support services behind authentication and IP allow-lists where feasible

Longer-term hardening

  • Egress-filter and alert on traffic to unsanctioned LLM API endpoints and resellers
  • Reduce internet-facing attack surface and maintain asset inventory for externally exposed services
  • Deploy WAF/IPS and rate-limiting tuned for high-tempo automated, agent-driven scanning
  • Monitor third-party and outsourced-worker access paths

Timeline of AI-assisted data-theft campaign against South Korean banks

  • Shinhan Bank confirms a breach affecting roughly 25,000 customers (press-reported); campaign window runs from late September.
  • KB Kookmin Bank discloses compromise of 119 customers' personal information; Hana Bank (89 customers) and BNK (11 outsourced workers) also reported affected.
  • CrowdStrike Intelligence report on ARTEX-driven targeting of South Korean finance is published (dated 7 October on the blog; press reports cite 8 October).
  • ARTEX developer Autumn-27 takes the tool closed source and announces no further releases or maintenance, citing abuse contrary to its purpose.
  • Public coverage reveals Claude Code session histories, ARTEX configuration files and Claude memory files in actor-controlled open directories; moderate-confidence assessment of a Chinese-speaking, financially motivated actor.
  • President Lee Jae Myung says signs of AI use have emerged in hacking incidents; police open a full-scale investigation. The Financial Services Commission warns of phishing and loan scams using the exposed data.

Sources cited for AI-assisted data-theft campaign against South Korean banks

Detection coverage for TL-2026-3137

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3137 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats