Home / Blog / ARTEX AI, Claude agents used in cyberattacks on South…
Tech News

ARTEX AI, Claude agents used in cyberattacks on South Korean banks

A Chinese hacker used ARTEX AI with DeepSeek v4.1-flash and Claude agents to breach Shinhan, KB Kookmin, and Hana Bank, exposing customer data in October 2026.

By Dillip Chowdary • Oct 10, 2026 • Source: BleepingComputer

ARTEX AI, Claude agents used in cyberattacks on South Korean banks

A Chinese-speaking hacker used the ARTEX AI penetration testing suite and Anthropic's Claude agents to launch cyberattacks against multiple South Korean banks earlier this month, exposing customer personal data and credit card information and triggering outages at several institutions. Security firm CrowdStrike confirmed the campaign in BleepingComputer's report, which also revealed that the attacker's own operational security failures exposed identifying details about the individual behind the intrusions.

This article covers how ARTEX AI was configured and deployed, which banks were hit and what was stolen, how CrowdStrike linked the infrastructure and partially identified the attacker, and what the incident means for AI-assisted offensive security tooling. It is relevant for security teams defending financial institutions, AI safety researchers, and anyone tracking the operationalization of large language models in real-world threat campaigns.

ARTEX AI: what actually changed

ARTEX AI was, until recently, an open-source agentic penetration testing suite developed in China. Following CrowdStrike's confirmation that the tool had been used in actual attacks against South Korean financial institutions, the project's developer decided to make ARTEX closed-source and discontinue further updates. The decision came directly in response to the public attribution linking ARTEX to the October 2026 bank breaches.

That closure has not removed the tool from circulation. Derivatives built from the existing codebase have already been released in both English and Korean, meaning the current version of ARTEX remains accessible in its original functional form. Security teams cannot treat the repository takedown as a meaningful remediation step — the attack-capable code is already distributed across forks.

ARTEX AI: how it works

ARTEX AI, Claude agents used in cyberattacks on South Korean banks
Illustration · Pexels

ARTEX AI functions as an agentic penetration testing framework that coordinates multiple AI models to carry out offensive operations. In the South Korean bank campaign, the attacker configured the ARTEX instance to use DeepSeek v4.1-flash as the primary large language model backend. Two additional models — GLM-5.3 from Zhipu AI and Grok 4.6 — were used for supplementary Claude Code sessions, allowing the attacker to run parallel AI-assisted workstreams across different parts of the operation.

CrowdStrike researchers identified the attacker's infrastructure by finding open directories that contained Claude Code session histories, ARTEX configuration files, and Claude memory files. The attacker likely accessed DeepSeek through the LLM API proxy or reseller service xcai[.]pro. Those session records provided a detailed record of the attacker's activities, with targets in the logs overlapping institutions named in previous reporting about financial-sector breaches — enabling high-confidence linking across incidents.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

ARTEX AI: why it matters now

This campaign marks a documented, confirmed case of a threat actor using an AI-native penetration testing platform in production attacks against critical financial infrastructure, not in a red-team exercise or proof-of-concept demonstration. The South Korean government responded with an emergency meeting and calls for immediate security measures across critical IT systems — a reaction that signals the attacks caused sufficient disruption to prompt a national-level response.

The ARTEX case illustrates a specific risk pattern: open-source AI attack tooling can be operationalized quickly, configured with commercially available LLM backends, and used by individuals rather than nation-state teams. The attacker appears to have worked alone and had no advance monetization plan — the session logs show them asking Claude to suggest Telegram channels focused on Korean data sales after the breach, implying the attack preceded any plan to extract financial value from the stolen data.

ARTEX AI: who is affected

The confirmed targets include three of South Korea's largest banks: Shinhan Bank, KB Kookmin Bank, and Hana Bank. Clients of those institutions had personal data and credit card information exposed, and some banks experienced system outages as a result of the intrusions. The breadth of the target list — spanning multiple major retail banking brands in a single campaign — suggests ARTEX-assisted automation enabled the attacker to pursue simultaneous or sequential intrusions rather than a single focused hit.

Beyond the direct victims, the incident affects any organization relying on financial infrastructure in the region, given that the attacker's session logs overlapped with targets from prior reported breaches. CrowdStrike's analysis also surfaced partial identity information about the suspected attacker: a 26-year-old Chinese national who studied at the South China University of Technology and reportedly lives in Maoming, Guangdong, China, based on a résumé the attacker created using the same AI tools used in the attacks. Researchers noted the attacker initially logged a 2007 birth date, making the personal details unreliable for confirmed attribution.

ARTEX AI: what to watch

The immediate technical concern is the continued availability of ARTEX derivatives in English and Korean. The closed-source decision by the original developer does not prevent existing forks from being maintained, extended, or reconfigured with newer LLM backends as those models become accessible through proxy services like xcai[.]pro. Security teams should treat ARTEX-pattern behavior — multi-model agentic sessions targeting financial authentication flows — as an active threat signature, not an emerging one.

CrowdStrike's finding that the attacker's operational security failure exposed their own identity through AI-generated artifacts is also worth tracking as a detection strategy. AI-native attackers using tools like Claude Code leave structured session histories, configuration files, and memory files that, when hosted carelessly, provide forensic-quality records. Defenders should monitor for exposed AI session artifacts in attacker infrastructure as a standard part of post-breach investigation, since those records enabled the cross-incident linking that produced the high-confidence attribution in this case.

Developer Action Items

  • ☐ Diff the official changelog for Anthropic / Claude / Framework 4.1 before you bump — APIs, defaults, and removed flags only.
  • ☐ Install through the vendor's documented channel in staging; keep a one-command rollback and time-box the canary.
  • ☐ Grep your repo for old flag names, lockfile pins, and plugin versions that the notes mark as breaking.
  • ☐ Prefer the first patch cut over the day-zero tag unless you have a reason to be on the leading edge.
  • ☐ If BleepingComputer did not name a region, plan, or SKU, screenshot the official availability line before you promise it to users.

ARTEX AI FAQ

Which banks were targeted in the ARTEX AI cyberattacks?

Shinhan Bank, KB Kookmin Bank, and Hana Bank were the confirmed targets. The attacks exposed client personal data and credit card information and caused system outages at some institutions.

What is ARTEX AI and who developed it?

ARTEX AI is an agentic penetration testing suite originally developed in China as an open-source project. After CrowdStrike confirmed its use in real-world attacks, the developer made it closed-source and stopped further updates.

Which AI models did the hacker use in the South Korean bank attacks?

The attacker used DeepSeek v4.1-flash as the primary LLM backend, with GLM-5.3 from Zhipu AI and Grok 4.6 for additional Claude Code sessions, likely accessing DeepSeek via the proxy service xcai[.]pro.

Has the attacker been identified?

CrowdStrike found partial identity details — suggesting a 26-year-old from Maoming, Guangdong, China who attended the South China University of Technology — but noted those details are not reliable enough to confirm identity, partly because the attacker initially logged a 2007 birth date.

Is ARTEX AI still available after the developer shut down the project?

Yes. English- and Korean-language derivatives built from the existing codebase have already been released, so the tool remains accessible in its current functional form despite the original repository going closed-source.

Sources

Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →