“The ARTEX instance used DeepSeek v4.1-flash as the primary LLM backend, and the threat actor supplemented this LLM with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions,” CrowdStrike explained.
How ARTEX AI and Claude agents were used
A Chinese-speaking hacker employed the ARTEX AI penetration testing suite together with Claude agents to carry out targeted intrusions against the South Korean financial sector earlier this month. CrowdStrike’s analysis shows the attacker ran ARTEX with DeepSeek v4.1-flash as the primary large language model (LLM) and supplemented it with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions. The researchers noted the threat actor likely accessed DeepSeek via the probable LLM API proxy or reseller xcai[.]pro. Open directories tied to the attacker contained Claude Code session histories, ARTEX configuration files, and Claude memory files—records that revealed the attacker’s operational activity.
Targets and immediate impact on South Korean banks
The campaign hit multiple Korean banks, including Shinhan Bank, KB Kookmin Bank, and Hana Bank. CrowdStrike reported that clients’ personal data and credit card information were exposed and that some institutions experienced system outages. The scale and nature of the breaches prompted the South Korean government to convene an emergency meeting and to call for immediate security measures for critical IT systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildWhat CrowdStrike found in attacker infrastructure and identity traces
Researchers recovered artifacts that allowed them to link the ARTEX-driven activity to financial-sector breaches named in earlier reporting, creating a high-confidence association between the attacker’s infrastructure and the incidents. Because the threat actor used the same AI tools to create a résumé, the exposed files included identification, contact details, and a Telegram account. Based on information in that résumé, CrowdStrike says the attacker may be a 26-year-old Chinese who studied at the South China University of Technology and lives in Maoming, Guangdong, China. The researchers also found the attacker initially provided a date of birth in 2007; CrowdStrike cautioned that although the personal details may belong to the individual behind the ARTEX-related activity, they are not reliable enough to confirm the threat actor’s identity.
The recovered session records show the attacker had no specific plan recorded to monetize the stolen data, and at one point asked Claude to propose Telegram data-sales groups focused on Korea.
ARTEX developer response and continued availability of derivatives
After security firms confirmed ARTEX had been used in real-world attacks, the project’s developer decided to make ARTEX closed-source and to discontinue further updates. Despite that decision, CrowdStrike noted the project’s code has already been used to create English- and Korean-language derivatives, meaning the ARTEX codebase remains available in its current form through those forks or copies.
What this means for South Korean banks, security teams, and open-source maintainers
- South Korean banks: faced with exposed client personal and credit card data and intermittent outages, the affected institutions and the government have moved to emergency coordination and ordered immediate security measures for critical IT systems.
- Security teams and incident responders: can draw on the recovered artifacts—Claude Code session histories, ARTEX configuration files, and Claude memory files—to map attacker behavior; CrowdStrike’s linkage to prior reporting gives investigators higher confidence when triaging related incidents.
- Open-source maintainers and vendor-resellers: the ARTEX developer closed the project after confirming misuse, yet English- and Korean-language derivatives persist; records also point to a likely API proxy/reseller (xcai[.]pro) as an access vector, underscoring the role of intermediary services in LLM-enabled toolchains.
The sequence of events—an attacker leveraging agentic AI tooling, the recovery of session-level artifacts that tied malware activity to specific targets, and the developer’s decision to close the project while derivatives already circulate—frames a narrow but consequential episode in fast-moving AI-enabled intrusions. The South Korean government’s emergency steps and CrowdStrike’s forensic detail are concrete responses; the lingering availability of ARTEX-derived code and the presence of intermediary LLM access points leave open a pointed question for defenders and policy makers alike: does closing an open-source project after abuse meaningfully reduce risk when functional copies and resellers remain?
Source: BleepingComputer — Hacker used ARTEX AI and Claude agents to target South Korean banks




