CrowdStrike Intelligence found Claude Code session histories, ARTEX configs and a CLAUDE.md in attacker open directories, showing a likely Chinese-speaking, financially motivated actor used the China-built open-source agentic pentest framework ARTEX (DeepSeek v4.1-flash primary, plus GLM-5.3 and Grok 4.6) to breach loan-inquiry and employee mobile systems at South Korean financial institutions from late September to early October 2026.
Key Takeaways
- ✓Window: late Sep to early Oct 2026; CrowdStrike attribution is moderate confidence, no named adversary
- ✓Model stack: DeepSeek v4.1-flash as ARTEX primary backend via likely reseller xcai[.]pro; GLM-5.3 and Grok 4.6 in Claude Code sessions
- ✓IOCs: 1 actor-controlled IP (38.244.50[.]120) plus 9 proxy IPs, with MITRE ATT&CK mapping
- ✓Reported impact: Shinhan 25,729 customers, Hana 89, Yegaram ~40,000 (press reports)
- ✓The upstream Autumn-27/ARTEX GitHub repo now returns 404
Key Decision Metrics at a Glance
Heavy Claude Code use: compare subscription limits and API bills
Compare 40 dev plans & simulate token costs vs $20/mo subscriptions
Project Links & Resources
Direct AccessIn-Depth Technical Analysis
CrowdStrike Intelligence reports that from late September to early October 2026 a likely Chinese-speaking, financially motivated actor (moderate confidence, unnamed) breached South Korean financial organizations, including a bank's loan-progress inquiry service for brokers and another bank's employee mobile work-support system, and exfiltrated data. Evidence came from the attacker's own open directories: Claude Code session histories, Claude memory files, ARTEX configs and a Chinese-language pentest CLAUDE.md. ARTEX is an open-source multi-agent autonomous pentest framework from China; its instance used DeepSeek v4.1-flash as the primary backend (likely via reseller xcai[.]pro), with GLM-5.3 and Grok 4.6 in additional Claude Code sessions. The report lists one actor-controlled IP plus nine proxy IPs with ATT&CK mapping. Press reports put Shinhan's exposure at 25,729 customers, Hana at 89 and Yegaram at about 40,000. Takeaway for builders: audit auxiliary and partner-facing systems for missing auth, ingest the IOCs, and never expose agent working directories, session logs or keys publicly.
Benchmark side-by-side against alternatives, or calculate monthly token cost vs subscription break-even.
Discussion & Comments
0Sign in to join the discussion
Connect with AI developers to exchange benchmark insights.