ThinkFacility Sign in
  1. Home
  2. News
  3. Anthropic

CrowdStrike says an attacker likely used the ARTEX AI agent against South Korean banks

The attacker left their Claude Code histories in an open directory, including the part where they asked Claude where to sell the data.

On October 7, 2026, CrowdStrike published its analysis of a campaign against South Korean financial organizations that ran from late September to early October. It says the campaign ended in stolen data, and that an AI agent running on the attacker's server was likely behind the Korean attacks.

The agent is ARTEX, which CrowdStrike describes as "an open-source Chinese-developed agentic penetration testing tool." The company assesses with moderate confidence that the person running it is a Chinese speaker, and financially motivated.

Who
CrowdStrike Intelligence
Targets
South Korean financial organizations
When
late September to early October 2026
Tool
ARTEX, with DeepSeek v4.1-flash, GLM-5.3 and Grok 4.6
Confidence
moderate

How CrowdStrike knows

The attacker left directories open on their own servers. Inside were Claude Code session histories, ARTEX configuration files and Claude memory files, which gave CrowdStrike a direct look at how the operation was run.

A tall pale concrete office tower with ribbon windows on a street corner under a white sky, cars parked along the curb and a city bus at the right
CrowdStrike's headquarters in Austin, Texas. Photo: ajay_suresh, CC BY 4.0, via Wikimedia Commons

ARTEX didn't run on Anthropic's models. CrowdStrike lists DeepSeek v4.1-flash as the main back end for ARTEX, with GLM-5.3 and Grok 4.6 added in other Claude Code sessions. Claude itself turns up in a different role, as an assistant the attacker asked for help.

the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups

From Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

The report doesn't say how Claude answered. In another session, the same user asked Claude to write a security researcher's résumé.

What was taken

CrowdStrike doesn't name the banks, and for what happened inside them it leans on industry reports. At one, the attacker reportedly got into a loan progress inquiry service used by financial brokers. At the other, it was a mobile system that employees use for work support.

South Korea's financial regulators had already sounded an alarm. On October 6, 2026, the Financial Services Commission and the Financial Supervisory Service issued a consumer alert about phishing scams following data breaches in the financial sector, and told banks to watch loan applications, new accounts and large transfers that involve stolen data.

Financial companies are instructed to make active use of the AI-based anti-phishing Sharing & Analysis Platform (ASAP)

From Press Releases

The alert doesn't mention ARTEX, and the CrowdStrike report doesn't cite the alert, so we can't say the two describe the same breaches. (They line up on timing and sector, which is as far as the saved pages go.)

CrowdStrike hasn't tied the activity to a named group. Its outlook is short: it expects adversaries "will likely continue to experiment" with AI tooling in their operations.

More on Anthropic

All Anthropic stories