Threats · 10h ago
CrowdStrike said a late-September to early-October 2026 campaign against South Korean financial organizations exfiltrated data, and it tied the activity to ARTEX and Claude session files found on attacker-controlled infrastructure.
The files included Claude Code session histories, ARTEX configuration data, and Claude memory files. In plain terms, that points to an operator using an AI-assisted pentesting workflow to carry out parts of the intrusion and then reuse the same state, instead of typing every step by hand.
The number of affected organizations is still not confirmed, but the reporting shows a repeatable workflow aimed at financial business systems, not a one-off breach. For banks and broker-adjacent services, the exposure is the speed and reuse an agentic tool can add when one case can become a template for the next.
3 sources covering this story
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Attackers used ARTEX and LLMs against South Korean financial organizations in a campaign that resulted in data exfiltration.
Chinese Hacker Deployed AI in Campaign Against South Korean Banks
CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance
CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial institutions that resulted in exfiltrated data.
Part of the PlainSec briefing for 2026-10-08