Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
Blog post from Crowdstrike
CrowdStrike Intelligence reported a late-September to early-October 2026 campaign involving data theft from several South Korean financial organizations, including reported compromises of a loan inquiry service and an employee mobile-work system. Investigators linked the activity to exposed attacker infrastructure containing ARTEX, a Chinese-developed open-source agentic penetration-testing tool, along with Claude Code histories, configuration files, and Chinese-language prompts that revealed the operator’s methods. The actor reportedly combined ARTEX with multiple large language models, including DeepSeek, GLM, and Grok, and used a two-server setup and numerous proxy addresses to support operations. CrowdStrike assessed with moderate confidence that the unidentified actor was likely Chinese-speaking and financially motivated, citing use of Chinese-language material and apparent searches for channels to sell stolen Korean data. Although session records included possible personal identifiers, the report stated that these details could not be conclusively tied to the attacker. The incident illustrates how AI-enabled tools may help threat actors accelerate conventional intrusion activity, while attribution and the total number of affected organizations remain unconfirmed.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.