A financially motivated campaign that used agentic AI tools to breach South Korean financial organizations and exfiltrate data.
Active from late September to early October 2026, the operation combined ARTEX, an open-source penetration testing platform developed in China, with multiple large language models.
Researchers recovered exposed operational files that documented the attacker’s infrastructure, prompts, and workflows.
CrowdStrike assesses with moderate confidence that the unidentified operator is likely Chinese-speaking and financially motivated.
However, researchers have not attributed the campaign to a named adversary, and the exact number of affected organizations remains unconfirmed.
The investigation centered on 38.244.50[.]120, an attacker-controlled server hosting an ARTEX instance.
An exposed Claude Code instruction file, available at the defanged address http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md, contained Chinese-language directions for penetration testing and referenced another attacker-controlled server in Hong Kong.
Investigators traced that reference to additional open directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files.
These artifacts exposed a two-server architecture: the Hong Kong server operated as the primary attacker environment, while 38.244.50[.]120 hosted the ARTEX instance likely used against Korean targets.
According to CrowdStrike, ARTEX used DeepSeek v4.1-flash as its primary model backend. Additional Claude Code sessions involved GLM-5.3 from Zhipu AI and Grok 4.6.
The operator likely accessed DeepSeek through xcai[.]pro, assessed as an LLM API proxy or reseller. These findings describe the attacker’s configuration, not evidence that the model providers knowingly supported the intrusions.
Industry reporting cited by CrowdStrike described compromises involving a loan progress inquiry service used by financial brokers and an employee mobile work-support system at separate banks.
Overlapping IP addresses reportedly connected activity across organizations, while ARTEX strings discovered in server-hosted HTML provided an early tooling clue.
Related Reuters reporting identified Shinhan Bank and KB Kookmin Bank among affected institutions.
Shinhan reported approximately 25,000 customers’ personal information compromised, while KB Kookmin reported leaks affecting 119 customers.
Reuters reported at least nine banks had disclosed attacks or appeared in local coverage; that broader count does not establish nine confirmed victims of this specific campaign.
Recovered sessions showed the operator asking Claude where criminals sell Korean breach information and seeking Korean Telegram data-sales groups.
Those requests support a profit-driven interpretation, although they do not establish that stolen records were successfully sold.
A separate session requested a security researcher résumé incorporating results from the ARTEX activity.
It supplied the alias YY, Telegram handle @YY520CN, and claimed ties to Maoming, Guangdong, and South China University of Technology.
Conflicting age information and unverifiable self-reported details prevent definitive identification. The same Telegram username appeared in research targeting an NFT gift marketplace and a possible Chinese payment platform.
CrowdStrike also published nine proxy addresses associated with the operation, including 101.53.80[.]20, 205.214.59[.]31, and 124.155.252[.]63.
Its MITRE ATT&CK mapping covers virtual private server acquisition, obtaining artificial intelligence capabilities, and proxy use.
The corresponding technique identifiers are T1583.003, T1588.007, and T1090, respectively, linking infrastructure preparation, AI capability acquisition, and proxy-mediated communications within the campaign.
The evidence demonstrates AI-assisted intrusion activity, not an independently operating AI attacker.
Exposed session logs reveal how a human operator combined agentic tooling, external models, and conventional infrastructure to support multiple intrusions within a short period, while leaving unusually detailed evidence of operational decisions behind.
| IOC | Description |
101.53.80[.]20 | Proxy IP address |
205.214.59[.]31 | Proxy IP address |
124.155.252[.]63 | Proxy IP address |
154.201.79[.]246 | Proxy IP address |
23.248.249[.]90 | Proxy IP address |
23.158.220[.]98 | Proxy IP address |
103.248.148[.]84 | Proxy IP address |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
A threat actor published a malicious version of the tensorlake npm package on October 8,…
A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…
A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…
16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…
Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…
wolfSSL has released wolfSSH version 1.6.0, which addresses five security vulnerabilities, including a critical flaw…