Skip to content

Executive Summary

A threat actor conducted a campaign targeting South Korean financial organizations between late September and early October 2026, resulting in data exfiltration. The activity involved the use of agentic AI tooling alongside traditional offensive methods, specifically leveraging ARTEX, an open-source pentesting tool developed in China, and Large Language Models (LLMs). Intelligence analysis uncovered threat actor-controlled directories containing Claude Code session histories, ARTEX configuration files, and Claude memory files, revealing operational methodology.
The infrastructure involved a two-server architecture: a Hong Kong-based IP address served as the primary control point, while another IP hosted the ARTEX instance. This ARTEX instance utilized DeepSeek v4.1-flash as a backend LLM, supplemented by GLM-5.3 and Grok 4.6 for additional session history collection. The threat actor also utilized several proxy IP addresses during these operations. Furthermore, the actors used Claude for reconnaissance, specifically querying about data sales and Telegram data groups. A profile suggesting a Chinese speaker and financial motivation was inferred based on the use of Chinese-developed tools and language prompts.

Facts Only

* A campaign targeting South Korean financial organizations occurred from late September to early October 2026.
* The threat actor utilized ARTEX, a Chinese-developed agentic penetration testing tool, alongside LLMs.
* Artifacts uncovered included Claude Code session histories, ARTEX configuration files, and Claude memory files.
* An IP address, 38.244.50[.]120, hosted an ARTEX instance and a Claude Code markdown document containing a Chinese-language pentesting prompt.
* A Hong Kong-based IP address contained additional open directories with session histories and configuration files.
* The infrastructure showed a two-server architecture: one location for control and another hosting the ARTEX instance.
* The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, supplemented by GLM-5.3 and Grok 4.6.
* Proxy IP addresses including 101.53.80[.]20, 205.214.59[.]31, 124.155.252[.]63, 154.201.79[.]246, 23.248.249[.]90, 23.158.220[.]98, 103.248.148[.]84, 203.160.133[.]172, and 209.209.85[.]38 were used during ARTEX activity.
* The threat actor inquired about selling data and finding Telegram data sales groups via Claude.
* One session contained personal details suggesting a user from Maoming, Guangdong, China, with the handle YY520CN.

Full Take

The narrative presents an intersection between cutting-edge AI tooling and established financial espionage, framed by geographically specific targeting. The core implication is that adversarial tradecraft is rapidly incorporating sophisticated, low-level automation tools like ARTEX into the workflow of financially motivated groups, augmented by LLMs for complex planning and data processing. This moves the threat landscape from traditional manual exploitation toward an era defined by AI-augmented intrusion capabilities.
The pattern observed is the embedding of specific tool artifacts—like ARTEX configurations and Claude session logs—directly within the communications infrastructure. This suggests that adversary infrastructure is not just used for command and control, but is meticulously documented to reveal methodologies. The attribution remains soft, relying on linguistic cues (Chinese prompts) and tool provenance (ARTEX), which introduces an ambiguity inherent in intelligence reporting.
The presence of detailed personal information linked to a specific Telegram handle during the AI interaction suggests a layered approach: using AI for the technical execution while potentially engaging in data brokerage or persona establishment through other channels. This forces an examination of where agency is being exercised—whether the operators are merely employing these tools, or if the tools themselves are shaping the capabilities of the threat actor to achieve goals that transcend simple data theft. What systems are in place to monitor and understand this fusion of open-source agentic AI and state-sponsored operational procedures? What risks does relying on pattern recognition alone introduce regarding human accountability when operating at this velocity?

From the original · CrowdStrike Blog

CrowdStrike Intelligence identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026.
Read the full story at crowdstrike.com
Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance | Huntaegis