CrowdStrike Links ARTEX AI Tool to Korean Finance Breaches
CrowdStrike says a suspected Chinese-speaking operator used ARTEX and commercial LLMs to steal data from South Korean financial firms in late 2026.
CrowdStrike reported a financially motivated campaign from late September to early October 2026 in which a suspected lone operator used ARTEX, an agentic penetration-testing tool from Chinese developer Autumn-27, and commercial large language models against South Korean financial organizations, resulting in data theft. Exposed infrastructure showed DeepSeek v4.1-flash as ARTEX’s main model, with Claude Code session records also using Zhipu AI’s GLM-5.3 and Grok 4.6; Claude was asked to locate Korean Telegram groups for selling stolen data, and The Hacker News said the operator ran ARTEX from Hong Kong IP 38.244.50.120. CrowdStrike has moderate confidence the unidentified actor is Chinese-speaking, profit-motivated, and not tied to a known threat group; alias YY remains unverified. Reported impact disagrees by source: Shinhan Bank about 25,000 customers, KB Kookmin Bank 119 customers per GBHackers only, and Yegaram Savings Bank about 40,000 people per Infosecurity Magazine only, while Cyber Security News also named Hana Bank, BNK Busan Bank, Hyundai Capital, and several savings banks and online lenders; a claim of nine banks is not confirmed for this operator. Core banking platforms were not compromised; weaker broker portals and employee systems were targeted, and South Korea’s Financial Services Commission warned customers on October 6 about phishing and loan scams. Autumn-27 later closed-sourced ARTEX and called the attacks unauthorized misuse. Separately, The Hacker News reported ZenoX’s account of SCARLET LOOP, an unrelated Portuguese-speaking actor’s credential-stuffing platform that validated 11,832 of 12,277,358 tested credentials across 3,968 domains.
- CrowdStrike reports a late September to early October 2026 campaign against South Korean financial organizations by a suspected lone operator, assessed with moderate confidence as Chinese-speaking and financially motivated, not linked to a…
- The operator used ARTEX, then an open-source agentic penetration-testing tool by Chinese developer Autumn-27, from Hong Kong IP 38.244.50.120; Autumn-27 later closed-sourced ARTEX and said the attacks were unauthorized misuse.
- Exposed infrastructure showed DeepSeek v4.1-flash (also styled V4.1 Flash) as ARTEX’s main model, with Claude Code sessions using Zhipu AI’s GLM-5.3 and Grok 4.6; Claude was asked to find Korean Telegram groups for selling stolen data.
- Victim counts differ by outlet: Shinhan Bank about 25,000 customers (GBHackers and Infosecurity Magazine); KB Kookmin Bank 119 customers (GBHackers only); Yegaram Savings Bank about 40,000 people (Infosecurity Magazine only). A figure of…
- Cyber Security News also named Hana Bank, BNK Busan Bank, Hyundai Capital, and several savings banks and online lenders; core banking was not compromised, while weaker broker portals and employee systems were targeted.
- South Korea’s Financial Services Commission warned customers on October 6 about phishing and loan scams. Mapped techniques include VPS acquisition, obtaining AI capabilities, and proxy use.
- Separately, The Hacker News cited ZenoX on SCARLET LOOP, a Portuguese-speaking actor’s agentic credential-stuffing platform that tested 12,277,358 credentials and validated 11,832 across 3,968 domains.
Coverage timelineoldest first · each row is one article
- · 11h agoFinancially Motivated Hacker Uses Agentic AI to Breach Multiple South Korean Finance Targets
GBHackers· 77
CrowdStrike says a financially motivated operator used agentic AI to breach South Korean banks and steal data.
- · 10h agoChinese Hacker Deployed AI in Campaign Against South Korean Banks
Infosecurity Magazine· 74
A suspected Chinese attacker used ARTEX and Claude to breach South Korean banks and steal customer data.
- · 10h agoSolo Hacker Used AI Tools to Breach South Korean Financial Organizations and Steal Data
Cyber Security News· 74