CrowdStrike Intelligence says a financially motivated operator used ARTEX, an open-source agentic penetration-testing tool developed in China, against South Korean financial firms from late September to early October 2026. The campaign stole data. Named victims in public reporting include Shinhan Bank and Yegaram Savings Bank. CrowdStrike has not tied the activity to a named threat group.
What happened
CrowdStrike found open directories on a Hong Kong IP that held Claude Code session histories, Claude memory files, and ARTEX configuration. A second address, 38.244.50.120, hosted the ARTEX instance suspected of the Korean attacks. The agent used DeepSeek as a primary model and, in other Claude Code sessions, GLM and Grok models. The operator also asked the model where Korean breach data is usually sold and for help finding Telegram sales groups.
On 8 October the developer, GitHub handle Autumn-27, said ARTEX would be closed and no longer updated because of misuse. Reuters reported the GitHub page was taken down. AhnLab separately said ARTEX v2 had grown into a multi-agent platform, with login screens observed on hundreds of internet-facing systems.
Who is affected
South Korean banks and savings institutions whose customer data was taken in this campaign. The wider issue is any organisation that has left an AI pentest agent, its session logs, or an API relay on an internet-facing host.
- Financial firms with customer-lookup or loan-inquiry services that sit outside core banking controls.
- Teams running agentic pentest tools (ARTEX or similar) against production without a locked scope and a human gate.
- Hosts that store Claude Code or other agent transcripts where an open directory would expose the whole operation.
What to do now
Inventory every AI agent and pentest runner that can reach customer systems, pull them off the public internet, and treat exposed session logs as sensitive incident data. Block or monitor the proxy pattern CrowdStrike described rather than relying on known-bad IP lists. If a client uses AI coding agents against live finance or identity systems, require an allow-list of targets and retain the transcripts.
Source: The Hacker News, 8 October 2026, citing CrowdStrike Intelligence, ARTEX used in South Korean financial data theft. Developer response: Reuters, 9 October 2026.
Also on the blog
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- Citrix NetScaler CVE-2026-107406 scores 9.5 on SAML deployments
- Cisco NX-OS CVE-2026-76471 and four more flaws score 9.8
- Japan web data leaks hit 119 in 2026, 81 since July
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.