securityaffairs.com 9 Oct 2026, 07:53 UTC

AI-Driven Hacker Used ARTEX to Target South Korean Financial Firms

AI-Driven Hacker Used ARTEX to Target South Korean Financial Firms

CROWDSTRIKE says an unidentified attacker targeted South Korean financial organisations from late September to early October 2026, stealing data that was being prepared for sale. Industry reports described breaches at several firms, including a bank’s loan-progress enquiry service used by financial brokers and another organisation’s employee mobile work-support system. The number of affected organisations has not been confirmed.

Researchers found directories on attacker-controlled servers containing Claude Code session histories, ARTEX configuration files and memory files, exposing the operator’s prompts and activity. ARTEX is described as a recently released open-source tool that uses AI agents to conduct penetration tests. The attacker combined it with large language models, including DeepSeek v4.1-flash, GLM-5.3 and Grok 4.6.

CrowdStrike linked the activity through overlapping IP addresses and ARTEX references, and assesses with moderate confidence that the operator was Chinese-speaking and financially motivated; it has not attributed the campaign to a specific group.

The exposed records show a two-server operation and testing against Korean financial targets. CrowdStrike also found the operator asking an AI assistant about selling stolen Korean data and finding Telegram groups where such data might be traded. The article reports that ARTEX’s developer, Autumn-27, later closed the source and stopped updates, saying the tool was intended for learning and research and was not connected to the attacks. CrowdStrike says AI tools may help financially motivated attackers carry out multiple intrusions more quickly.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline