# AI-assisted data-theft campaign against South Korean banks: CrowdStrike finds ARTEX agentic pentest tool, Claude Code session histories and Claude memory files on attacker infrastructure

> From late September to early October 2026 an unattributed, likely Chinese-speaking, financially motivated actor used the China-developed open-source agentic pentesting framework ARTEX, backed by LLMs, plus Claude Code to breach South Korean financial organizations and exfiltrate customer data. CrowdStrike assesses attribution with moderate confidence; South Korean police have opened a full investigation after President Lee Jae Myung said signs pointed to AI use.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3137
- **ID:** TL-2026-3137
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)

## Description

CrowdStrike Intelligence identified infrastructure tied to a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. Analysis of threat-actor-controlled open directories exposed Claude Code session histories, ARTEX configuration files and Claude memory files (including a /.claude/CLAUDE.md file), giving direct insight into the operator's methodology. The campaign was active from late September to early October 2026. CrowdStrike published its report on 7-8 October 2026 (sources differ on the exact day).

ARTEX is described as a recently released open-source, LLM multi-agent autonomous penetration-testing framework developed in China by Autumn-27. The ARTEX instance believed responsible for the Korean intrusions was hosted at 38.244.50.120 and used DeepSeek v4.1-flash as its primary LLM backend. The operator supplemented it with GLM-5.3 (Zhipu AI) and Grok 4.6 in additional Claude Code sessions. A Hong Kong-based IP served as the primary attacker-controlled infrastructure, which makes a two-server architecture. The domain xcai.pro is assessed as an LLM API proxy/reseller used to reach DeepSeek. Nine additional proxy IPs were used for operational security. CrowdStrike also lists VPS acquisition for C2 and acquisition of ARTEX as resource-development activity.

Reported operational activity includes breaching a loan progress inquiry service at one bank and compromising an employee mobile work-support system at another organization. The Claude Code sessions show the operator asking where to sell the stolen Korean data and for help finding Korean Telegram groups that trade breach data. CrowdStrike's public reporting identifies no CVEs and does not detail the initial-access vector or exfiltration method; third-party write-ups only generically describe automated scanning and exploitation of exposed web applications and services.

Media reports name Shinhan Bank (about 25,000 customers, confirmed 30 September), KB Kookmin Bank (119 customers, disclosed 2 October), Hana Bank (89 customers), BNK (11 outsourced workers) and Yegaram Savings Bank, with Taipei Times reporting at least nine banks targeted. Exposed data included names, phone numbers, annual income, calculated loan limits and 66 resident registration numbers. Counts come from press reports and differ between outlets. South Korea's Financial Services Commission warned of follow-on phishing and loan scams using the exposed data. The ARTEX developer subsequently closed the source and announced no further releases or maintenance, stating that abuse violates the tool's original purpose.

CrowdStrike assesses with moderate confidence that the actor is a financially motivated Chinese speaker, based on use of the Chinese-developed ARTEX tool and Chinese-language prompts. Reporting also cites unverified self-identifying details in a prompt, and these are deliberately not reproduced here. CrowdStrike SVP Adam Meyers noted the campaign let one human target many customers in a very short period using AI. The Chinese Foreign Ministry said China opposes hacking activity. Anthropic and the Korean police did not respond to press requests; one outlet notes Anthropic has detection and account-banning processes for Claude misuse.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583.003 Acquire Infrastructure: Virtual Private Server
- T1588.007 Obtain Capabilities: Artificial Intelligence
- T1190 Exploit Public-Facing Application
- T1090 Proxy

## Sources

- [CrowdStrike: Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)
- [SecurityWeek: In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years](https://www.securityweek.com/in-other-news-ai-used-in-korean-bank-breaches-poem-guided-botnet-empire-admin-gets-40-years/)
- [The Hacker News: ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms](https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html)
- [Taipei Times: S Korean banks likely hacked by China-based actor: CrowdStrike](https://www.taipeitimes.com/News/front/archives/2026/10/09/2003865655)
- [Yahoo News: Korean Bank Hacker Asked Claude Where to Sell the Stolen Data, CrowdStrike Says](https://www.yahoo.com/news/world/articles/korean-bank-hacker-asked-claude-110751209.html)
- [Aviatrix Threat Research Center: ARTEX AI Pentesting Tool Used Against South Korean Banks 2026](https://aviatrix.ai/threat-research-center/artex-ai-pentesting-south-korean-financial-firms-2026/)
- [Tech Insider: South Korea Bank Hacks: CrowdStrike Ties AI Agent to China](https://tech-insider.org/south-korea-bank-hacks-ai-agent-crowdstrike-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3137
