CrowdStrike has uncovered a targeted campaign against South Korean financial institutions that leverages advanced AI-powered tooling. In a report published on October 7, 2026, researchers detail how a financially motivated threat actor used a new open-source agentic penetration testing tool called ARTEX in conjunction with Large Language Models (LLMs) like Claude. The campaign, which began in late September 2026, has already resulted in data exfiltration from several organizations. This incident provides concrete evidence of threat actors operationalizing agentic AI to enhance the efficiency and scale of their attacks, a long-anticipated evolution in the threat landscape.
The threat actor, assessed with moderate confidence to be a Chinese-speaking individual or group, is financially motivated. Their targets include multiple South Korean banks and financial services companies. In one case, a loan progress inquiry service was breached, and in another, an employee mobile work-support system was compromised. The attacks demonstrate a clear intent to steal sensitive financial and personal data.
The actor's use of ARTEX, a tool developed in China, combined with analysis of their infrastructure, points to their likely origin. Researchers discovered open directories on a Hong Kong-based IP address containing Claude Code session histories and ARTEX configuration files, giving them a direct look into the attacker's methods and AI prompts.
This campaign showcases the integration of AI into the cyberattack lifecycle. The use of an agentic tool like ARTEX, powered by an LLM, automates many tasks that would typically require manual effort. The attacker likely used the tool for:
T1595 - Active Scanning.T1190 - Exploit Public-Facing Application.The discovered session histories show the actor interacting with the LLM, refining the attack, and directing the ARTEX agent. This represents a significant leap in tradecraft, moving beyond simple scripting to a more dynamic, AI-driven attack process.
The immediate impact includes the exfiltration of sensitive data from multiple South Korean financial firms, affecting both customers and employees. The broader strategic impact is more significant. This campaign serves as a proof-of-concept for other threat actors, demonstrating that agentic AI tools are no longer theoretical but are being used effectively in the wild. This will likely lower the barrier to entry for less-skilled attackers and increase the tempo and sophistication of attacks across all sectors. Security teams must now prepare to defend against adversaries who can operate at machine speed.
The source articles did not contain specific, actionable Indicators of Compromise.
Detecting AI-driven attacks may require looking for new patterns:
Inbound Traffic Filtering.Decoy Environment by allowing safe analysis of such tools.Using behavior-based detection on web and API traffic can help identify the anomalous patterns generated by AI-powered attack tools.
Mapped D3FEND Techniques:
Implementing aggressive rate limiting and traffic filtering at the network edge can disrupt and slow down automated attack tools.
Mapped D3FEND Techniques:
Rigorously hardening the configuration of all public-facing applications and APIs reduces the attack surface available to automated tools.
Mapped D3FEND Techniques:
To defend against AI-driven attacks like those using ARTEX, organizations must move beyond static signatures and implement Web Session Activity Analysis. This involves deploying an API security or WAF solution capable of learning the normal sequence, timing, and logic of user interactions with your applications. The ARTEX tool, while intelligent, will exhibit patterns distinct from human users—specifically, machine-speed execution of logical attack paths. A behavior-based system can flag a 'session' that enumerates API endpoints, tests for injection flaws, and attempts to exfiltrate data within seconds as anomalous. This technique is critical for detecting the new class of automated, agentic attacks that can bypass traditional defenses.
A fundamental defense against automated tools like ARTEX is aggressive Inbound Traffic Filtering, specifically through API rate limiting and geo-blocking. For the South Korean financial firms, this would involve setting strict thresholds on the number of requests allowed per second from a single IP to critical APIs like the loan inquiry service. This forces the automated tool to slow down, increasing the chances of detection and giving defenders time to react. Additionally, since the actor's infrastructure was in Hong Kong, geo-blocking traffic from regions where you do not conduct business can be an effective, albeit broad, control. This simple but powerful technique acts as a speed bump for automated attacks, disrupting their core advantage of speed and scale.
The campaign targeting South Korean financial firms using ARTEX begins.
CrowdStrike publishes its report detailing the use of ARTEX and LLMs in the attacks.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.