Next upPhysical AI VC <> Founders Pitch Night #SFTechWeek @Mission Robotics
News

CrowdStrike links ARTEX and LLMs to South Korean finance intrusions

CrowdStrike says exposed development records tie an unnamed actor’s South Korean finance intrusions to ARTEX and several large language models, extending the evidence beyond earlier official suspicion.

D
Oct 8, 2026 · 1 min read

CrowdStrike said an unnamed threat actor used the open-source ARTEX penetration-testing system and several large language models in a campaign against South Korean financial organizations that resulted in data being exfiltrated. The security company said the activity ran from late September to early October 2026, but it did not confirm how many organizations were affected or identify them.

The CrowdStrike investigation adds technical evidence to DataPhoenix’s earlier coverage of South Korea’s bank-hack investigation, which described a government probe and possible AI use. CrowdStrike’s forensic account goes beyond that earlier official suspicion by tying exposed development records and specific infrastructure to ARTEX.

Actor-controlled open directories exposed Claude Code session histories, ARTEX configuration files and Claude memory files, CrowdStrike said. According to the company, those records showed a two-server setup: a Hong Kong-based IP address served as the main attacker-controlled infrastructure, while 38.244.50[.]120 hosted the ARTEX instance likely used in the South Korean attacks.

CrowdStrike said the ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend. The actor also used GLM-5.3 and Grok 4.6 in additional Claude Code sessions. ARTEX’s public repository describes it as an LLM-driven, multi-agent autonomous penetration-testing system with planner and worker agents.

CrowdStrike assessed with moderate confidence that the actor was likely a Chinese speaker and financially motivated, citing the use of the Chinese-developed tool and Chinese-language prompts. It did not attribute the operation to a named adversary. Personal details and a Telegram username appeared in one exposed session, but CrowdStrike said the available information could not definitively connect those details to the actor.

The report did not disclose the amount or categories of data that CrowdStrike said were exfiltrated. CrowdStrike also said the organizations found in the exposed records overlapped with those named in industry reporting but were not necessarily the same set.

More news