Back to News
SecurityAI Understanding briefing

CrowdStrike details AI tooling in South Korean bank breaches

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations, uncovering Claude Code session histories and ARTEX configuration files that reveal the threat actor's use of agentic AI tooling.

4 min readRead the linked source
Source-provided image accompanying CrowdStrike details AI tooling in South Korean bank breaches
Source referenceSource recorded
Publisher
crowdstrike.com
Source type
Linked source — primary-source status has not been established.
ContextUnderstand this in 60 seconds

Key terms

API (Application Programming Interface)
A structured way for one software system to send requests to and receive responses from another system.
Large Language Model (LLM)
A language model trained on massive text corpora to generate and analyze text.
Memory (Agent Memory)
Stored context an AI agent uses across steps or sessions to improve continuity.
Test yourselfAI Ethics Quiz

What happened

CrowdStrike Intelligence published a report detailing infrastructure associated with a campaign that breached multiple South Korean financial organizations between late September and early October 2026. The analysis uncovered open directories on threat actor-controlled servers containing Claude Code session histories, ARTEX configuration files, and Claude memory files. These artifacts revealed that the attacker used ARTEX, a Chinese-developed open-source agentic penetration testing tool, alongside large language models including DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. The report identifies a two-server architecture involving a Hong Kong-based primary infrastructure and a secondary server hosting the ARTEX instance, while noting that the specific number of affected organizations remains unconfirmed.

CrowdStrike Intelligence identified infrastructure linked to a campaign targeting South Korean financial organizations from late September to early October 2026. The campaign resulted in data exfiltration, with specific breaches reported in a loan progress inquiry service and an employee mobile work-support system. While industry reports suggest multiple organizations were affected, CrowdStrike states the exact number remains unconfirmed as of the report's publication.

Analysis of threat actor-controlled open directories revealed Claude Code session histories, ARTEX configuration files, and Claude memory files. These files provided direct insight into the attacker's methodology, showing the use of ARTEX, a recently released open-source agentic penetration testing tool developed in China. The ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend, supplemented by GLM-5.3 and Grok 4.6 for additional sessions.

The infrastructure analysis identified a two-server architecture: a Hong Kong-based IP address served as the primary attacker-controlled infrastructure, while a separate IP address hosted the ARTEX instance likely responsible for the attacks. The attacker used multiple proxy IP addresses to obscure their location. In one session, the attacker asked Claude for assistance in finding Korean Telegram data sales groups and for creating a security researcher résumé to cover their tracks.

CrowdStrike assesses with moderate confidence that the threat actor is likely a Chinese speaker and financially motivated, based on the use of the Chinese-developed ARTEX tool and observed Chinese-language prompts. Personal details found in a prompt, including a name, phone number, and Telegram handle, likely belong to the attacker, but the report notes that currently available information cannot definitively associate these details with the threat actor.

Source details: crowdstrike.com ↗

Why it matters

This report provides concrete technical evidence that agentic AI tools are being operationalized by financially motivated threat actors to accelerate the pace and scope of cyberattacks against critical financial infrastructure. By documenting the specific use of ARTEX and LLMs to conduct multiple intrusions in a short timeframe, CrowdStrike highlights a significant evolution in adversarial tradecraft. The discovery of session histories where the attacker queried LLMs for methods to sell stolen data and create cover identities underscores the practical utility of AI in lowering the barrier for complex, multi-target campaigns. This development signals that AI is no longer just a defensive tool but a central component of offensive operations, requiring updated security strategies to detect and mitigate AI-assisted threats.

The report demonstrates that AI tooling can enable a single, financially motivated threat actor to conduct multiple intrusions within a short time span, significantly enhancing operational tempo. This challenges traditional security models that assume such rapid, multi-target campaigns require larger, more sophisticated state-sponsored groups.

The use of agentic AI tools like ARTEX alongside LLMs represents a concrete shift in adversarial tradecraft. By automating penetration testing and vulnerability exploitation, AI lowers the skill barrier for executing complex attacks, making it easier for smaller actors to target high-value sectors like finance.

The discovery of session histories where the attacker used LLMs to plan data sales and create false identities highlights the dual-use nature of AI in cybercrime. It shows that AI is not only used for technical exploitation but also for the operational and logistical aspects of a cyberattack, including post-exploitation activities.

Interactive Mechanism

Interactive Mechanism: How It Actually Works

Explore the underlying technology behind this development interactively.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interactive Concept Check+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

What to watch next

Monitor for further attribution of the threat actor, as CrowdStrike notes the identity is not definitively confirmed despite personal details found in prompts. Watch for regulatory responses in South Korea and China regarding the use of open-source AI tools for malicious purposes. Additionally, observe whether other financial institutions report similar breaches involving ARTEX or comparable agentic AI frameworks, and track the development of defensive AI tools designed to counter these specific offensive capabilities.

Further attribution efforts may clarify whether this activity is linked to a specific state-sponsored group or remains a financially motivated independent actor. The personal details provided in the prompts may offer leads for law enforcement, though CrowdStrike notes the association is not definitive.

Regulatory bodies in South Korea and China may respond to the use of open-source AI tools for malicious purposes. This could lead to new restrictions on the distribution or use of agentic AI tools, or increased scrutiny of LLM API providers.

Security vendors may develop new detection capabilities specifically tailored to identify AI-assisted attacks, such as monitoring for the use of known agentic AI tools or unusual patterns in LLM API usage. Financial institutions may also update their security protocols to account for the increased speed and scale of AI-enabled threats.

Related guides & quizzes

Found this useful?