The server running the intrusions had a browsable folder, and what was in it looked like the operator's CV
2026-10-10AI
CrowdStrike traced a data-theft campaign against South Korean financial firms to an operator driving ARTEX, an open-source agentic pentesting tool, across several large language models. The research exists because the attacker left their own working directories readable.