A new report from CrowdStrike has unveiled a concerning cyber threat actor believed to be operating from China, exploiting artificial intelligence (AI) tools in a campaign that successfully exfiltrated sensitive data from several South Korean financial institutions. This alarming revelation underscores the evolving landscape of cyber threats, where traditional hacking techniques live alongside state-of-the-art AI technologies.
CrowdStrike’s investigation revealed that the attackers utilized a recently released open-source pentesting tool known as ARTEX, developed in China, alongside the Claude AI model by Anthropic. This strategic partnership between AI capabilities and traditional offensive tactics facilitated an extensive operation running from late September to early October 2026.
The primary use of ARTEX by the threat actor was to identify vulnerabilities within victim organizations and to compromise their services. In a notable tactic, the attacker even solicited assistance from Claude in locating Korean Telegram groups where stolen data could potentially be sold. This indicates a calculated approach aimed at maximizing the financial gains from the exfiltrated data while tapping into modern communication platforms.
CrowdStrike highlighted that the integration of AI tools into the attack framework exemplifies a significant shift in adversarial tradecraft. As they noted in a blog published on October 7, “The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft.” This observation suggests that financially motivated cybercriminals can conduct multiple intrusion attempts in rapid succession, driven by AI’s efficiency and capability to manage large-scale operations.
The investigation has led CrowdStrike to assess, with moderate confidence, that the threat actor communicates in Chinese and is financially driven. This contextualization of the attacker adds a layer of insight into the potential motivations behind the cyber operations.
Through their analysis, researchers at CrowdStrike were able to trace all the attacks back to a single IP address, which enabled them to identify how the AI tools were deployed during the campaign. This IP address hosted an instance of ARTEX and an open directory containing a Markdown document that offered a Chinese-language pentesting prompt. This document specified parameters for how the large language model (LLM) should carry out pentesting activities, showcasing the operational level of sophistication involved in these cyber assaults.
The ARTEX instance used the DeepSeek v4.1-flash version as its primary LLM backend. Additionally, the threat actor appeared to supplement this prominent AI tool with GLM-5.3 from the Chinese firm Zhipu AI and Grok 4.6 for further Claude Code sessions. This layering of AI resources indicates a robust operational capacity, allowing the attacker to exploit numerous vulnerabilities in various systems.
Moreover, the investigation unearthed another IP address linked to the same threat actor, located in Hong Kong. This address was identified as a part of the attacker-controlled infrastructure and contained additional open directories with Claude Code session histories and ARTEX configuration files. A specific Claude Code session revealed personal information, including a Telegram username, YY520CN, associated with a location in Maoming, Guangdong, China. This information likely pertains to the threat actor conducting the ARTEX-related operations, reinforcing suspicions about their geographical roots.
As the campaign unfolded, it became apparent that it resulted in large-scale data breaches affecting several South Korean financial firms, including Shinhan Bank and Yegaram Savings Bank. Reports indicate that the breaches have impacted 25,000 and 40,000 individuals, respectively, as noted by The Straits Times, a Singapore-based publication. At one of the impacted banks, the threat actor reportedly accessed a loan progress inquiry service utilized by financial brokers, while at another institution, the attack compromised a mobile work-support system intended for employees.
CrowdStrike has been diligent in stating that the total number of organizations affected by the cyber onslaught remains unconfirmed at the time of the report’s release. Meanwhile, in response to the escalating threat, South Korea’s Financial Services Commission issued a consumer alert on October 6, warning customers of the compromised firms to remain vigilant against potential phishing attacks and loan scams that could arise in the wake of the data breaches.
The agency added that the affected organizations will continue to assess the extent of the data breaches, promising to keep the public updated as investigations unfold. This evolving situation underscores the urgent need for vigilance in cybersecurity, particularly as cybercriminals increasingly leverage advanced technologies to elevate the scale and impact of their attacks.

