CYBERSECURITY researchers have disclosed a targeted campaign against South Korean financial organisations that leveraged an AI pentesting tool called ARTEX to facilitate data theft. The activity, observed from late September to early October 2026, involved exfiltration of data after threat actors used ARTEX in conjunction with large language models (LLMs).
CrowdStrike notes the campaign was detected after researchers found open directories on a Hong Kong-based IP address exposing Claude Code session histories, Claude memory files, and ARTEX configuration data. The operation has not been attributed to a named threat actor, though evidence points toward a Chinese-speaking operator motivated by financial gain.
ARTEX is described as a multi-agent, autonomous pentesting system developed by Autumn-27. Investigators observed a two-server architecture: a Hong Kong-based IP acting as the campaign’s backbone, and another IP 38.244.50[.]120 hosting the ARTEX instance behind the Korean attacks. The ARTEX deployment reportedly used DeepSeek v4.1-flash as the main LLM backend, with Z[.]ai’s GLM-5.3 and SpaceXAI’s Grok 4.6 providing supplementary capabilities.
Researchers believe the actor accessed DeepSeek through a likely LLM API reseller at xcai[.]pro. In Claude Code sessions, the attacker even queried Claude about data-breach markets and Telegram data-sale groups, signalling intent to monetise stolen data. Autumn-27 has since moved ARTEX to closed source, stating the tool’s misuse contradicts its original purpose and that there will be no further updates or public releases. The report highlights how AI-enabled tooling is accelerating threat activity, while noting that attribution remains uncertain.