Unknown Threat Actor Uses Artex To Target South Korean Finance
Unknown Threat Actor Uses Artex To Target South Korean Finance
CrowdStrike Intelligence has identified infrastructure associated with a targeted campaign against South Korean financial organizations that resulted in exfiltrated data. The campaign was active from late September to early October 2026.
Key Findings:
- Analysis of threat actor-controlled open directories uncovered Claude Code session histories, ARTEX configuration files, and Claude memory files, providing direct insight into the threat actor’s operational methodology and tooling.
- The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed in adversarial tradecraft.
- The threat actor leveraged ARTEX, a recently released open-source agentic penetration testing tool developed in China, alongside large language models (LLMs).
Incident Overview:
According to industry reports, beginning in late September 2026, several South Korean financial organizations experienced data breaches. At one affected bank, the threat actor reportedly breached a loan progress inquiry service used by financial brokers. At another bank, the threat actor compromised an employee mobile work-support system.
Technical Details:
Reporting suggested the attacker used ARTEX based on references to the string ARTEX in HTML files observed on a reportedly threat actor-controlled server. The IP address 38.244.50 was associated with the activity described and hosted an ARTEX instance and open directory containing a Claude Code markdown document. The markdown document contained a Chinese-language pentesting prompt that specified how the LLM should conduct pentesting activities.
Conclusion:
While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated. This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.
For more detailed information, please visit: Read full article