A suspected China-based threat actor used AI-assisted tooling in a campaign that successfully exfiltrated data from South Korean financial organisations, researchers at CrowdStrike disclosed. The attacker leveraged ARTEX, a new open-source pentesting agent, alongside Claude AI to guide the campaign, which ran from late September to early October 2026.
ARTEX was used mainly to discover vulnerabilities and compromise targeted services, while Claude was pressed to locate Korean Telegram data-sale groups to broker the stolen information. CrowdStrike characterised the approach as an indication of evolving adversarial tradecraft, enabling multiple intrusions in a short time frame for financial gain. They assess with moderate confidence that the attacker is a Chinese speaker and financially motivated.
Researchers linked all attacks to the same IP address, which hosted an ARTEX instance and an open directory containing a Claude Code markdown with a pentesting prompt in Chinese. The setup used DeepSeek v4.1-flash as the primary LLM backend, supplemented by GLM-5.3 (from Zhipu AI) and Grok 4.6 for additional Claude Code sessions.
Another attacker-controlled Hong Kong–based IP address appeared in the documentation and was deemed to host the primary infrastructure, including Claude Code session histories, ARTEX configuration files and Claude memory data. One Claude Code session reportedly included personal details such as a Telegram username and a Guangdong location, which CrowdStrike flagged as likely belonging to the actor.
The campaign purportedly breached data from several South Korea–based financial firms, including Shinhan Bank (affecting about 25,000 people) and Yegaram Savings Bank (about 40,000 people), per The Straits Times. Impacts included a breached loan progress inquiry service and an employee mobile work–support system, though total affected organisations remained unconfirmed at publication.
South Korea’s Financial Services Commission issued a consumer alert on 6 October, warning customers to watch for phishing and loan-scam activity and noting that affected organisations would provide updates as investigations progressed.