CrowdStrike Intelligence says an agentic AI penetration-testing system called ARTEX was repurposed in a targeted campaign that led to data exfiltration from South Korean financial organizations in late September to early October 2026. The firm traced operational artifacts to an internet-exposed infrastructure and published a technical chain of evidence that links Claude Code session histories, ARTEX configuration files, and a two-server architecture hosted from a Hong Kong-based backbone.
How CrowdStrike reconstructed the campaign
CrowdStrike discovered the activity after finding a set of open directories on a Hong Kong-based IP address that exposed Claude Code session histories, Claude memory files, and ARTEX configuration files. The company reported the campaign was active from late September to early October 2026 and that it resulted in data exfiltration from South Korean financial firms.
The analysis identified a two-server architecture: a Hong Kong-based IP functioning as the campaign backbone, and an ARTEX instance hosted at IP address 38.244.50[.]120 that CrowdStrike suspects was behind the attacks targeting Korean organizations. CrowdStrike also said the campaign has not been attributed to any known threat actor or group, but that evidence points to a suspected Chinese-speaking operator motivated by financial gain.
ARTEX: architecture, models, and the developer response
ARTEX is described in CrowdStrike's findings as a large language model multi-agent autonomous penetration system developed by Autumn-27. CrowdStrike reported the ARTEX instance used multiple LLM backends:
- DeepSeek v4.1-flash as the primary LLM backend
- Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 as supplementary models
- A likely LLM API reseller, xcai[.]pro, was suspected as the access conduit for DeepSeek
Autumn-27 responded to reports of misuse by stating that ARTEX was intended to help enterprises and organizations conduct security risk tests within the scope of authorized assets and to improve security protections. Citing the reality of tool abuse, Autumn-27 said it would convert ARTEX to closed source, stop updating the project, and cease releasing any future versions or maintenance support.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSCARLET LOOP: a parallel AI-driven credential-stuffing operation
Separately, ZenoX disclosed an AI-orchestrated credential stuffing and account takeover platform it attributes to a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP. ZenoX described an automated four-step workflow used to hijack accounts at scale:
- Target discovery and qualification using an AI classifier (targets: Brazilian loyalty, corporate incentives, and gift card platforms)
- Obtaining credentials specific to each target (from infostealer logs and data leaks)
- Login execution with an AI agent and an anti-detection browser to bypass automation defenses
- Exfiltration of successful credentials to a private Telegram channel in the format "✅ {{url}} {{user}}:{{password}}"
ZenoX reported the platform used a mix of LLMs and local models — OpenAI GPT-5.6 and GPT-5.5 for query generation and classification, DeepSeek-V4-Pro and DeepSeek-V4-Flash for browser agents, Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, GLM-5.1, and a local Google gemma-4-26B-A4B model served at 127.0.0[.]1:1237. An LLM agent with 46 automation tools drove an instrumented Firefox that spoofed canvas, WebGL, time zone, language, geolocation and viewport attributes and used outsourced captcha solving. ZenoX also described an "AUTO Mode" that removes the AI model from the loop after repeated successful logins to conserve model tokens; "Model reasoning is expensive and slow," the company said.
ZenoX's analysis of an internet-exposed server hosting the platform found 12,277,358 credentials had been tested; 11,832 credentials were classified as valid across 3,968 domains.
What South Korean financial firms, security teams, and Autumn-27 face
- For South Korean financial firms: CrowdStrike reported data exfiltration tied to the ARTEX-driven campaign between late September and early October 2026. Firms will watch for indicators associated with ARTEX activity — exposed Claude Code session artifacts, ARTEX configuration files, and connections to the Hong Kong backbone and 38.244.50[.]120 — and for signs of their data appearing for sale on Telegram or other marketplaces.
- For security teams and technologists: the campaign demonstrates an operational linkage between exposed LLM session files and offensive automation. CrowdStrike found the threat actor queried Claude about where threat actors sell Korean breach data and asked for assistance finding Korean Telegram data sales groups. The sessions referenced a Telegram account named "@YY520CN" and the name "YY," though CrowdStrike said these details are not definitive proof of actor identity. Teams will likely parse exposed session histories and ARTEX configuration artifacts as part of incident response.
- For Autumn-27 and tool maintainers: Autumn-27's decision to move ARTEX to closed source and to stop future releases reflects a concrete developer response to documented abuse. Autumn-27 emphasized the original research and learning intent of ARTEX and said malicious use violated that purpose.
The two disclosures — CrowdStrike on ARTEX-linked data exfiltration and ZenoX on SCARLET LOOP's credential-stuffing platform — together illustrate adversaries' use of multi-model LLM stacks, instrumented browsers and automation to scale operations. CrowdStrike's work stops short of a firm attribution, but it provides a chain of technical artifacts — exposed Claude session and memory files, ARTEX configs, and a Hong Kong-based backbone including 38.244.50[.]120 — that defenders can hunt for and forensic teams can analyze.
Read the original report: https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html




