CrowdStrike: attacker used open-source AI pentest agent ARTEX plus Claude Code to breach South Korean financial firms
CrowdStrike Intelligence found Claude Code session histories, ARTEX configs and a CLAUDE.md in attacker open directories, showing a likely Chinese-speaking, financially motivated actor used the China-built open-source agentic pentest framework ARTEX (DeepSeek v4.1-flash primary, plus GLM-5.3 and Grok 4.6) to breach loan-inquiry and employee mobile systems at South Korean financial institutions from late September to early October 2026.
- β’Window: late Sep to early Oct 2026; CrowdStrike attribution is moderate confidence, no named adversary
- β’Model stack: DeepSeek v4.1-flash as ARTEX primary backend via likely reseller xcai[.]pro; GLM-5.3 and Grok 4.6 in Claude Code sessions
- β’IOCs: 1 actor-controlled IP (38.244.50[.]120) plus 9 proxy IPs, with MITRE ATT&CK mapping
- β’Reported impact: Shinhan 25,729 customers, Hana 89, Yegaram ~40,000 (press reports)
- β’The upstream Autumn-27/ARTEX GitHub repo now returns 404



