Threats · 10h ago

CrowdStrike Ties ARTEX to South Korean Finance Hits

CrowdStrike said a late-September to early-October 2026 campaign against South Korean financial organizations exfiltrated data, and it tied the activity to ARTEX and Claude session files found on attacker-controlled infrastructure.

The files included Claude Code session histories, ARTEX configuration data, and Claude memory files. In plain terms, that points to an operator using an AI-assisted pentesting workflow to carry out parts of the intrusion and then reuse the same state, instead of typing every step by hand.

The number of affected organizations is still not confirmed, but the reporting shows a repeatable workflow aimed at financial business systems, not a one-off breach. For banks and broker-adjacent services, the exposure is the speed and reuse an agentic tool can add when one case can become a template for the next.

Timeline

Sources

3 sources covering this story

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories