| |

ARTEX AI Agent Attacks on South Korean Banks: What CrowdStrike’s Leaked Session Logs Reveal

One operator, an open-source agentic pentesting tool built in China, and a stack of rented language models were enough to break into several South Korean lenders in a matter of weeks. The attacker’s own AI session logs, left in open directories, are how CrowdStrike reconstructed the campaign. The tool’s author has since closed the source, but copies are still circulating.

DataWater Threat Intelligence Desk | Published October 11, 2026 | 8-minute read

Threat level: High (confirmed intrusions)

New McAfee Banner
Keeper Confetti Image

What: A financially motivated campaign against South Korean financial institutions that used ARTEX, an open-source agentic penetration-testing tool developed in China, together with DeepSeek, GLM, Grok and Claude Code sessions. No CVE has been published for the intrusions.

Status: Data was stolen from several lenders between late September and early October 2026, according to CrowdStrike. The total number of affected organizations is unconfirmed.

Deadline: There is no CISA KEV deadline because no CVE is involved. In Korea, lawmakers plan to question the heads of five major banks at a parliamentary audit on October 19, according to one report.

Fix: There is no patch for a tool. Block CrowdStrike’s published indicators, hunt for them in logs back to mid-September, and review every internet-facing broker, loan-status and mobile-workforce portal.

Key takeaways

  • The ARTEX AI agent attacks are real intrusions, not a lab demo. CrowdStrike says a single, likely Chinese-speaking, financially motivated operator exfiltrated data from several South Korean financial firms from late September to early October 2026.
  • The attacker mixed several models. ARTEX ran on DeepSeek v4.1-flash, likely bought through the reseller xcai[.]pro, with GLM-5.3 and Grok 4.6 used in additional Claude Code sessions.
  • Claude was used for the business side of the crime. The operator asked Claude where Korean breach data is usually sold and to help find Korean Telegram data-sale groups, according to CrowdStrike.
  • Public IoCs exist: ten IP addresses, one domain and an exposed CLAUDE.md file on port 18899. Hunt for them now.
  • Closing the source did not remove the tool. ARTEX’s developer stopped updates and made the project private, but English and Korean derivatives remain available.

Executive Summary

An AI-assisted operator hit multiple banks in one short campaign, and the evidence came from the attacker’s own AI logs.

On October 7, CrowdStrike’s Counter Adversary Operations team published research on a campaign against South Korean financial institutions. Its analysts found attacker-controlled servers with open directories holding Claude Code session histories, ARTEX configuration files and Claude memory files. Those files described the targeting step by step. CrowdStrike tied every attack to one server that hosted an ARTEX instance, and named a second, Hong Kong-based server as the main attacker infrastructure.

Korean reporting cited by The Register names five affected lenders: Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank. At one bank, the intruder reportedly got into a loan-progress inquiry service used by brokers. At another, an employee mobile work-support system was compromised. CrowdStrike assesses with moderate confidence that the operator is Chinese-speaking and motivated by money, and it has not linked the activity to a named group.

The bottom line: agentic tooling let one person run several intrusions in a short window. Treat the published indicators as a hunting job today, and treat the broader lesson, that low-skill attackers can now move at team speed, as a planning assumption for 2027.

Why This Matters to CISOs and Security Leaders

The speed problem has arrived in production. CrowdStrike’s assessment is that AI tooling let a financially motivated actor carry out several intrusions in a short period. DataWater has tracked AI agents breaking things in controlled settings, from OpenAI’s research agents escaping a sandbox to four frontier labs reporting similar failures. This case is different: a criminal pointed the tooling at banks on purpose and took data.

The targets were the side doors. Neither reported entry point was a core banking system. A broker-facing loan-status portal and a staff mobile app are the kind of secondary, internet-facing services that tend to get less testing. An agent that scans and probes tirelessly will find them.

Model guardrails were not the control that mattered. The main ARTEX backend was a DeepSeek model reportedly reached through a reseller, and the operator switched between four model families. Any single provider’s abuse controls were easy to route around. Your own detection and exposure management are what count.

Executive insight

Ask your team this week: “Which of our internet-facing apps for brokers, partners or staff mobile access had a penetration test in the last 12 months?” If the list has gaps, an automated attacker will find them before your next annual test does.

The Timeline

Date (2026) What happened
Late September Campaign begins; breaches at several South Korean financial firms start, per CrowdStrike and industry reporting
Early October Activity continues; data exfiltrated from multiple organizations
Tuesday, Oct 6 South Korea’s Financial Services Commission issues a consumer alert about phishing and loan scams (per Infosecurity Magazine)
Wednesday, Oct 7 CrowdStrike publishes its research and IoCs
Thursday, Oct 8 Korean lawmakers approve summoning five bank heads to a parliamentary audit (per The Register, citing Korean press)
Oct 9–10 ARTEX developer closes the source and stops updates; English and Korean derivatives remain available (Security Affairs, BleepingComputer)
Monday, Oct 19 Scheduled parliamentary audit of bank cybersecurity lapses (single-source)

The operator’s AI agent kept a diary. Leaving it on an open server is how the defenders got to read it.

Vulnerability & Exploit Analysis

What ARTEX is

ARTEX is an agentic penetration-testing framework released as open source in China. It hands reconnaissance, vulnerability discovery and exploitation steps to a large language model, which decides what to try next. CrowdStrike linked this campaign to ARTEX through the string “ARTEX” in HTML files on the attacker’s server, along with configuration files for the tool. According to Security Affairs, the developer says the project was meant for learning and research and that the attacks have nothing to do with them. The source is now closed and updates have stopped.

How the operator used it

The attacker used ARTEX mainly to find weaknesses in, and break into, specific services at the victim organizations. A CLAUDE.md file on the ARTEX server held a Chinese-language pentesting prompt that told the model how to run its tests. CrowdStrike has not named any CVEs exploited in the intrusions, so which software flaws were used is unknown.

Models and services involved

Component Role in the campaign Source
ARTEX Agentic pentesting framework that ran the intrusions CrowdStrike
DeepSeek v4.1-flash Primary LLM backend for the ARTEX instance, likely reached via xcai[.]pro CrowdStrike
GLM-5.3 (Zhipu AI) Used in additional Claude Code sessions CrowdStrike
Grok 4.6 Used in additional Claude Code sessions CrowdStrike
Claude / Claude Code Session tooling; asked about Korean data-sale markets and Telegram groups, and to write a résumé describing the ARTEX results CrowdStrike

Affected and fixed versions do not apply here: this is a campaign built on a tool, not a software flaw with a patch.

What nobody is talking about
AI agents write down everything. Session histories, memory files and prompt files are an attacker’s operational notes, and this operator stored them in open directories. The same is true inside your company: every internal agent deployment produces memory and session files that record what was accessed and why. Decide now who owns those logs, how long they are kept and whether your SOC can search them, because they will be the first thing incident responders ask for.

Threat Intelligence Breakdown

Attribution: No named group. CrowdStrike assesses with moderate confidence that the operator is Chinese-speaking and financially motivated, based on the Chinese-built tool and Chinese-language prompts. A résumé-writing request in the logs contained personal details that CrowdStrike believes probably belong to the operator, but it says it cannot yet tie them to the actor definitively. BleepingComputer noted the details contain internal contradictions. Korean police are investigating whether one person or an organized group was responsible, according to The Register.

Infrastructure: A two-server setup. A Hong Kong-based IP served as the main attacker infrastructure (CrowdStrike did not publish that address). A second server, 38.244.50[.]120, ran the ARTEX instance and exposed an open directory on port 18899. CrowdStrike maps the activity to MITRE ATT&CK T1583.003 (virtual private servers), T1588.007 (obtaining AI capabilities) and T1090 (proxy).

Indicators of compromise (CrowdStrike, defanged):

Type Indicator Context
IP address 38.244.50[.]120 Attacker-controlled ARTEX host; open directory on port 18899
URL path hxxp://38.244.50[.]120:18899/.claude/CLAUDE.md Chinese-language pentesting prompt file
IP address 101.53.80[.]20 Proxy used during ARTEX activity
IP address 205.214.59[.]31 Proxy
IP address 124.155.252[.]63 Proxy
IP address 154.201.79[.]246 Proxy
IP address 23.248.249[.]90 Proxy
IP address 23.158.220[.]98 Proxy
IP address 103.248.148[.]84 Proxy
IP address 203.160.133[.]172 Proxy
IP address 209.209.85[.]38 Proxy
Domain xcai[.]pro Likely LLM API proxy/reseller used to reach DeepSeek

How to read these: proxy IPs rotate quickly, so a miss today does not clear you. Search firewall, WAF and VPN logs back to at least mid-September. Outbound DNS or proxy hits on xcai[.]pro from your own network deserve a look too, since it points to unsanctioned LLM API use whatever the intent.

Enterprise Impact: What’s Actually at Risk

Customer data: Shinhan Bank reported about 25,000 affected customers, according to two outlets citing Korean and Singaporean press. Yegaram Savings Bank reported about 40,000 (single-source). KB Kookmin and Hana reported 119 and 89 respectively (single-source). CrowdStrike says the full victim count is unconfirmed. BleepingComputer reported that exposed data included personal and credit card information at some banks, with service outages in some cases.

Follow-on fraud: CrowdStrike’s logs show the operator researching where to sell Korean breach data. Korea’s financial regulator has warned affected customers to expect phishing and loan scams. Banks outside Korea that share customers or broker networks should watch for the same pattern.

Regulatory exposure: Korean bank chiefs face a parliamentary audit. Elsewhere, a breach traced to an under-tested partner portal will draw the same question from regulators and boards: why was that system reachable and untested?

Security program assumptions: Annual pentests and quarterly scans were sized for human attackers. An agent that probes continuously changes the math on how fast exposed weaknesses get found.

What Security Leaders Should Do Next

Today

  1. Block and hunt the ten IPs and xcai[.]pro across firewalls, WAFs, VPN concentrators and DNS logs, going back to mid-September.
  2. List every internet-facing app for brokers, partners and staff mobile access. Those were the entry points in this campaign.
  3. Financial institutions with Korean operations or partners: brief fraud and customer-support teams on phishing and loan-scam lures tied to the breaches.

Within 48 hours

  1. Look for agent-style scanning: high-volume, fast-changing request patterns against a single app from rotating proxy IPs, often followed by targeted exploitation.
  2. Check outbound data volumes from portal and mobile back-end servers for unusual transfers since late September.
  3. Ask your MSSP or MDR provider whether they have ingested CrowdStrike’s indicators and what detections they have for automated, AI-driven probing.

Long-term

  1. Move secondary apps into continuous testing. If attackers can test you every day, annual coverage of the main site is not enough.
  2. Govern your own AI agents’ logs. Set retention, access control and SOC searchability for agent session and memory files.
  3. Add “AI-assisted single operator” to your threat model and tabletop it: one person, many simultaneous intrusions, short dwell time.

Get zero-day alerts before they hit the headlines

DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.

Read more briefings

Winners and Losers

Better positioned More exposed
Teams with continuous attack-surface monitoring of partner and mobile apps Organizations that test only their main customer site once a year
SOCs that already ingest vendor IoC feeds automatically Teams that copy indicators by hand from blog posts days later
Defenders who can read attacker AI logs when they leak, as CrowdStrike did Operators who leave agent memory files on open servers
Banks with fraud teams briefed on post-breach scam waves Customers of breached lenders now facing targeted phishing

Final Executive Takeaway

This was a capacity problem, not a model problem.

One operator, an open-source agent and rented models produced several bank intrusions in a few weeks. Switching off any single AI provider would not have stopped it. Fewer exposed, under-tested apps and faster detection would have.

Hunt the indicators today. Inventory your side doors this week. Plan for attackers who never get tired.

Frequently Asked Questions

What is ARTEX AI?

ARTEX is an open-source agentic penetration-testing tool developed in China that lets a language model run reconnaissance and exploitation steps. CrowdStrike found ARTEX at the center of an October 2026 campaign against South Korean banks. Its developer has since closed the source and stopped updates, but derivative versions remain available.

Which South Korean banks were hit in the ARTEX AI campaign?

Korean reporting cited by The Register names Shinhan Bank, KB Kookmin Bank, Hana Bank, Yegaram Savings Bank and BNK Busan Bank as affected by the ARTEX AI campaign. CrowdStrike says the total number of affected organizations is not confirmed.

How was Claude used in the ARTEX bank attacks?

According to CrowdStrike, the operator behind the ARTEX bank attacks ran Claude Code sessions and asked Claude where Korean breach data is typically sold, for help finding Korean Telegram data-sale groups, and to write a résumé describing the ARTEX results. The ARTEX instance’s primary model was DeepSeek v4.1-flash, not Claude.

Who is behind the ARTEX AI attacks on South Korean banks?

The ARTEX AI attacks on South Korean banks have not been attributed to a named group. CrowdStrike assesses with moderate confidence that the operator is a Chinese speaker driven by financial gain. Personal details found in the operator’s AI logs have not been definitively tied to the attacker.

What are the indicators of compromise for the ARTEX campaign?

CrowdStrike’s ARTEX campaign indicators are the ARTEX host 38.244.50[.]120 (port 18899), nine proxy IPs (101.53.80[.]20, 205.214.59[.]31, 124.155.252[.]63, 154.201.79[.]246, 23.248.249[.]90, 23.158.220[.]98, 103.248.148[.]84, 203.160.133[.]172, 209.209.85[.]38) and the LLM reseller domain xcai[.]pro.

Is there a CVE or CISA deadline for the ARTEX AI bank attacks?

No. CrowdStrike has not tied the ARTEX AI bank attacks to any specific CVE, so there is no CISA Known Exploited Vulnerabilities entry or federal deadline. The defense is blocking the published indicators, hunting for them in logs, and reducing exposed, under-tested applications.

Does closing ARTEX’s source code stop the threat?

No. The ARTEX developer made the project closed-source and stopped updates after the bank attacks, but BleepingComputer reports English and Korean derivatives built from the existing code are still available. Organizations should assume ARTEX-style agentic tooling stays in circulation.

Sources

Primary source: CrowdStrike, “Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance” (October 7, 2026; IoCs and MITRE mapping). Additional reporting reviewed: BleepingComputer (October 10); The Register (October 8, citing The Korea Times for victim names and counts); Infosecurity Magazine (October 8, citing The Straits Times); Security Affairs (October 9). Per-bank victim counts are single-source where noted. Reflects public reporting as of October 11, 2026.

Similar Posts