CrowdStrike published research on 7 October into a data-theft campaign against South Korean financial organisations, running from late September into early October. The operator drove ARTEX, an open-source agentic penetration-testing tool from China, across several large language models.

As with the ransomware affiliate whose staging server had an unauthenticated file listing, the research exists because of what the attacker left readable. Browsable folders on the operator's servers held session logs, configuration files and the model's memory notes — and, among the exposed prompts, personal details that CrowdStrike believes probably identify the operator, without saying so outright.

ARTEX is not a model

The distinction matters for reading any of this correctly.

ARTEX is an orchestration layer. It plans and sequences the steps of an intrusion and routes the reasoning-heavy parts out to external language models. It supplies the loop; somebody else's model supplies the thinking.

In this campaign the model stack was led by DeepSeek, with two other models in supporting roles. The operator also had Claude Code session logs and memory notes on the server.

That second sentence is the one being misreported, so it is worth being exact. Claude Code appearing in a toolset shows it was on the operator's machine. It does not show that Anthropic's models performed the intrusions, and CrowdStrike's own account puts DeepSeek at the centre of the stack. An attacker who uses four tools has used four tools.

There is a disclosure to make here: this site is written with Claude's assistance, which is noted on our editorial policy page. That is a reason to be careful with this particular detail, not a reason to leave it out.

What it actually was

CrowdStrike describes a person steering AI tooling, not an autonomous attack. The argument it makes is narrower and more interesting than "AI did the hacking": that tooling of this kind let one financially motivated actor run multiple intrusions in a short span.

That is a claim about throughput, not capability. Nothing here required a technique that a competent human could not perform. What changed is how many targets one person could work in a fortnight.

Attribution is given at moderate confidence: a financially motivated Chinese speaker, on the basis of tool choice and Chinese-language prompts. No named group. The infrastructure ran from a machine in Hong Kong, with a second server hosting the ARTEX instance.

The numbers, and why not to add them

Reported victims include named South Korean banks, and public reporting counts at least nine financial institutions targeted since late September.

The record counts need handling. Different outlets, citing different sources, give different figures: roughly 25,000 affected customers at one bank, 119 at another, 40,000 at a third, and a separate figure of around 68,000 records across a wave of bank incidents that South Korean authorities are investigating for AI involvement.

Those come from separate reports about overlapping but not identical events. They are not components of a total, and anyone adding them is inventing a number. The honest summary is that several institutions were hit, the largest disclosed figure is in the tens of thousands of customers, and the full scope is not public.

The tool is gone, which changes less than it sounds

ARTEX's maintainer, who goes by a handle online, moved the project to closed source on 8 October, citing misuse, and stopped updating it.

That is a defensible response and a limited one. The code has been public; anyone who wanted a copy has one. What closing it changes is the supply of future updates and the ease of casual adoption, which is not nothing — a tool that is one clone away from working gets used by people who would not otherwise build one.

The broader question is the one that keeps arriving in different shapes. An agentic pentest tool is useful for the same reason it is dangerous: it automates the part of an intrusion that used to need an experienced person. Whether access is gated by a vendor's verification, by a licence, or by a maintainer's decision to close the repository, the gate is somebody's judgement about who is asking — and we wrote recently about how little is behind that judgement.

What to do

  • For financial-sector defenders in the region, CrowdStrike's indicators are the immediate item. The campaign window is recent and the infrastructure is documented.
  • Do not reach for AI-specific detection. The intrusions used ordinary techniques faster; what catches them is what catches those techniques.
  • Plan for throughput rather than novelty. If one actor can now run nine intrusions where they used to run one, the thing under strain is triage capacity, not the detection logic.
  • Treat the OPSEC failure as a reminder, not a reassurance. Two campaigns in a week were documented because the operator left a directory listing enabled. The ones that do not are the ones nobody writes about.

What is not established

  • Who the operator is. CrowdStrike's confidence is moderate, and the personal details in the prompts are described as probably, not certainly, theirs.
  • How many organisations were actually compromised, as opposed to targeted.
  • Whether the separate incidents being investigated by South Korean authorities are the same campaign.
  • What role each model in the stack played, beyond DeepSeek being central.
  • Whether any connection exists to incidents reported in Japan. Nothing published establishes one.