What did CrowdStrike publish, and when?

The dated primary source is CrowdStrike’s 7 October 2026 Intelligence blog post. We opened it on 9 October. It says CrowdStrike identified infrastructure tied to a targeted campaign against South Korean financial organisations, that the activity ran from late September to early October 2026, and that it resulted in exfiltrated data. The evidence it emphasises is open directories under attacker control: Claude Code session histories, ARTEX configuration files and Claude memory files.

CrowdStrike cites industry reporting, including a 4 October Korea Herald English item, for the start of the bank breaches. At one bank, that reporting said a loan-progress inquiry service used by brokers was reached. At another, an employee mobile work-support system was reached. CrowdStrike’s own sentence on scope is cautious: “As of this writing, the number of organizations affected remains unconfirmed.”

This is a threat-intel note about agentic tooling in an intrusion, not a model launch and not a takedown of a false-front influence shop. The nearer influence-operations story on this site is OpenAI’s Category 5 false-front report, which is a different class of abuse.

What tooling does CrowdStrike say was used?

ARTEX, in CrowdStrike’s words, is a recently released open-source agentic penetration-testing tool developed in China. The Hacker News, on 8 October, attributes the project to a developer using the handle Autumn-27 and describes it as an LLM multi-agent pentest system that calls external models rather than shipping its own weights. We did not open a live ARTEX repository; The Hindu’s Reuters story says the GitHub page was later taken down.

CrowdStrike says a two-server layout appears in the Claude Code sessions: a Hong Kong-based IP as the primary attacker-controlled host, and a second address hosting the ARTEX instance it links to the Korean activity. The ARTEX instance, it writes, used DeepSeek v4.1-flash as the primary backend and added GLM-5.3 from Zhipu AI and Grok 4.6 for further Claude Code sessions. DeepSeek access, CrowdStrike assesses, likely went through an API proxy or reseller it names as xcai.pro. The post also lists proxy addresses in an IOC table. We are not reprinting that table.

The sessions also show the operator asking Claude where stolen Korean data is typically sold and how to find Korean Telegram sales groups. That is a reported prompt theme, not a how-to. For the product-side boundary on tool-using agents, see agent sandboxing and prompt injection; those guides are about limiting what an agent can reach, not about reproducing this campaign.

How does CrowdStrike describe the actor?

CrowdStrike does not assign a named adversary. The attribution sentence is: the actor “is likely a Chinese speaker and financially motivated,” at moderate confidence, “based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts.”

Separately, one Claude Code session asked for a security-researcher résumé that included bullet points about the ARTEX-related activity. CrowdStrike lists personal details that appeared in that prompt: a name rendered as YY, a Telegram handle, age 26, a date of birth the operator first gave as 2007-09-22, South China University of Technology, and Maoming, Guangdong, China. The same Telegram handle, CrowdStrike writes, also appeared in sessions about a Telegram NFT marketplace and in activity against a possible Chinese payment platform.

The firm’s closer on identity is the sentence that matters: those details “likely belong to the threat actor,” but “currently available information cannot definitively associate these details with the threat actor.” The Hacker News repeats that caveat. Some later news stories shortened it to a China-based 26-year-old suspect. That shorter line is not CrowdStrike’s conclusion. The Hindu’s 9 October Reuters piece is one of the stories that restates the résumé details more firmly than the original note.

What happened to ARTEX after the report?

The Hacker News, dated 8 October, says misuse prompted Autumn-27 to take ARTEX closed source. It quotes the developer saying ARTEX was “originally designed for the purpose of learning and research,” meant for authorised tests, and that “the ARTEX project will no longer be updated and will be converted to a closed source,” with no further public versions or maintenance. The same article says the handle @YY520CN posted a denial on Telegram on 8 October; that message is THN’s report, not a finding we verified on Telegram.

The Hindu published a Reuters story at 09:06 IST on 9 October. It quotes Autumn-27 on GitHub, on Thursday, converting the project to closed source, opposing illegal use, and disclaiming responsibility for unlawful conduct. Reuters, via The Hindu, also writes that ARTEX’s GitHub page had been taken down, that at least nine South Korean banks had been disclosed or reported as targets since late September, and that South Korean police had opened a probe. President Lee Jae Myung’s call for a response is in that Reuters copy. Those political and victim-count lines are not in CrowdStrike’s 7 October post.

The Hacker News names Shinhan Bank and Yegaram Savings Bank among firms that lost data. CrowdStrike does not name those banks. Keep the names in THN’s column. South Korea’s Financial Services Commission and Financial Supervisory Service, THN writes, warned consumers about phishing and loan scams that can follow a leak.

What should readers not infer?

ARTEX is an agent that calls other models. It is not itself DeepSeek, Claude or Grok, and a model vendor appearing in session logs is not the same as that vendor endorsing the operator. A downloaded pentest agent that can call tools is a provenance and sandbox problem, closer to ProjectDiscovery’s backdoored-model write-up than to a new foundation-model release.

Do not treat the résumé prompt as a confirmed identity, a charged suspect, or a reason to contact the named university. Do not treat Autumn-27’s closed-source note as proof the developer ran the campaign; both THN and Reuters say the developer denied a link. Do not treat “Chinese-developed tool” as state attribution. CrowdStrike’s moderate-confidence line is about language and tooling, not about a government service.

What is not established?

We did not retrieve the open directories, replay Claude sessions, or confirm which bank systems were reached. CrowdStrike has not published a victim total. Bank names, the “at least nine” figure, the police probe and the presidential remark come from THN or Reuters, not from the 7 October note. The Telegram denial is THN’s. The GitHub takedown is Reuters’s check via The Hindu.

This article does not describe how ARTEX finds or exploits a service, and it does not reprint CrowdStrike’s full IOC list. It is an evidence review of three pages opened on 9 October. It is not incident response for a named bank and not a ranking of ARTEX against other pentest agents.

Common questions

Did CrowdStrike name the attacker?

No. It does not assign a tracked group. It gives a moderate-confidence language and motive assessment, and it says personal details from a résumé prompt cannot be definitively associated with the operator.

Is ARTEX still open source?

Not according to The Hacker News on 8 October and The Hindu’s Reuters story on 9 October. Both say Autumn-27 converted the project to closed source and stopped public updates. Reuters reported the GitHub page taken down. We did not find a live public tree.

Which banks does CrowdStrike name?

None. The 7 October post leaves the victim count unconfirmed. Shinhan and Yegaram appear in The Hacker News. The “at least nine” line is Reuters via The Hindu.

THE TAKEAWAY

What to remember

Use CrowdStrike’s 7 October note for the campaign window, the ARTEX-plus-LLM tooling and the unnamed, moderate-confidence actor. Use THN and The Hindu for the closed-source follow-up and for bank names they — not CrowdStrike — printed. Do not promote the résumé prompt to an identified person.

Sources & further reading

  1. Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance ↗
  2. ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms ↗
  3. Chinese developer makes ARTEX AI agent closed-source after Korean bank hack ↗
How this story was made

Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.

Our editorial standards
Back to all stories