Analysis: the hacker who targeted South Korean banks is likely Chinese-speaking, financially motivated, and used LLMs and open-source Chinese agentic tool ARTEX
First reported by Crowdstrike ·
The use of advanced AI agent tools like ARTEX by financially motivated attackers lowers the barrier to sophisticated cyberattacks.
CrowdStrike Intelligence has identified a cyberattack campaign targeting South Korean financial organizations between late September and early October 2026. The campaign, which resulted in data exfiltration, utilized the open-source, Chinese-developed agentic tool ARTEX alongside large language models (LLMs). Evidence includes Claude Code session histories, ARTEX configuration files, and memory files found on a threat actor-controlled server. The threat actor is likely a Chinese speaker and financially motivated, indicated by the use of ARTEX and observed Chinese-language prompts. The attacks involved a two-server architecture, with a Hong Kong-based IP as primary infrastructure and another IP hosting the ARTEX instance. LLM backends included DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6, likely accessed through the xcai[.]pro proxy.
The observed attack campaign showcases a significant evolution in adversarial tradecraft by integrating agentic AI tooling with traditional hacking methods. The reliance on LLMs for tasks such as pentesting, as evidenced by the detailed prompt found, suggests a move towards more automated and potentially more effective attack execution. This development signifies a new phase in cyber warfare where AI is not just a target but also a sophisticated weapon.
This incident highlights the growing threat posed by financially motivated actors leveraging sophisticated, readily available AI tools. The use of Chinese-developed tools and Chinese-language prompts suggests a specific regional threat actor, but the accessibility of such tools means similar attacks could emerge from various sources. Organizations, particularly in the finance sector, must bolster defenses against AI-augmented threats and monitor for emerging agentic tools.
AI-written summary. May contain errors.