ARTEX: AI pentest tool used to steal South Korean bank data
ARTEX agentic pentest South Korean banks

ARTEX: AI pentest tool used to steal South Korean bank data

An open-source agentic penetration-testing tool was used in a real data-theft campaign against South Korean financial firms. CrowdStrike says the activity ran from late September into early October 2026 and ended in exfiltration.

What happened

CrowdStrike Intelligence found threat-actor infrastructure, including open directories with Claude Code session histories and ARTEX configuration. ARTEX is a Chinese-developed multi-agent pentest system that drives large language models. In this case the operator paired it with more than one model backend. The actor also asked a model where Korean breach data is sold.

The campaign is not attributed to a named group. CrowdStrike assesses, with moderate confidence, that the operator is a Chinese speaker and financially motivated. After the misuse became public, the ARTEX developer said the project would go closed source and would not be maintained. That does not remove copies already in attacker hands.

Who is affected

South Korean financial organisations hit in this wave. CrowdStrike says the number of victims is still unconfirmed. Local reporting has named banks, but those counts should not be treated as CrowdStrike-confirmed totals. The broader lesson is not geography. Any shop that leaves admin panels, loan portals, or broker tools on the internet is now in scope for an agent that can iterate without a human on every step.

  • Tooling: ARTEX plus commercial and reseller LLM access.
  • Outcome reported by CrowdStrike: data exfiltration.
  • Attribution: unknown actor, moderate-confidence financial motive.

What to do now

Treat agentic pentest tools as attacker capability, and put the same controls on internet-facing finance and broker apps that you would put on a VPN. Watch for unusual authenticated sessions, bulk export, and new admin accounts. If you run an internal AI assistant with shell or browser access, assume a stolen prompt or a stolen token can point that assistant at your own estate.

Source: CrowdStrike, Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ASOS breach: stolen employee login exposed customer contacts
ASOS employee credential theft customer contacts