Breaking
Cyber CrimeDeveloping Story

AI Agent Tooling Used in Bank Hacks

CrowdStrike attributes a data theft campaign against South Korean financial firms to a Chinese-speaking actor who paired an agentic pentesting tool with multiple LLMs.

··3 hours ago·6 min read
a computer keyboard with a padlock on top of it
Photo by Sasun Bughdaryan on Unsplash

An open-source pentesting agent released in China, combined with several large language models, formed the backbone of a data-theft campaign against South Korean financial organizations, according to research published by CrowdStrike. The cybersecurity firm reported that the activity ran from late September to early October 2026, and that it has assessed with moderate confidence that the person behind it is a Chinese speaker who was financially motivated.

The firm's findings connect the intrusions to a single IP address and describe an attacker who leaned on AI tooling to discover vulnerabilities, compromise services, and then try to find buyers for the information taken.

One IP and an Agent Called ARTEX

CrowdStrike reported that a suspected China-based threat actor used ARTEX, described as a recently released open-source agentic pentesting tool developed in China, alongside Anthropic's Claude AI model. The tool was the primary instrument for discovering vulnerabilities and compromising specific services inside victim organizations.

All of the attacks were linked back to one IP address, which is what let the researchers uncover the AI deployment at the center of the campaign. That address hosted an ARTEX instance and an open directory containing a Claude Code markdown document, according to the firm's account.

Inside that document was a Chinese-language pentesting prompt setting out how the large language model should carry out pentesting activities. The ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend.

The operator supplemented that backend with GLM-5.3, from Chinese firm Zhipu AI, and Grok 4.6 for additional Claude Code sessions, CrowdStrike said.

A Hong Kong Address and Open Directories

A second IP address, also controlled by the threat actor and based in Hong Kong, appeared in the same document. CrowdStrike assessed that this address served as the primary attacker-controlled infrastructure.

That Hong Kong address was found to contain additional open directories holding Claude Code session histories, ARTEX configuration files, and Claude memory files. The exposed directories are what gave the researchers visibility into how the tooling had been configured and used across the campaign.

One Claude Code session contained a prompt that included personal details: the Telegram username YY520CN and a location of Maoming, Guangdong, China. CrowdStrike said it is likely these details belong to the threat actor who conducted the ARTEX-related activity.

What CrowdStrike Told the Public

In a blog published on October 7, the firm described the combination of tooling it had observed and framed the activity as an example of how AI can be folded into offensive operations.

“The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft. This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span,” CrowdStrike wrote.

— CrowdStrike, in a blog published on October 7

The firm's assessment that the actor was a Chinese speaker and financially motivated carries moderate confidence. CrowdStrike also emphasized that the total number of organizations affected remained unconfirmed at the time it published its findings.

Breaches Reported at Two Banks

The campaign reportedly resulted in data being exfiltrated from a number of South Korea-based financial firms. Among them were Shinhan Bank and Yegaram Savings Bank, which reported breaches affecting 25,000 and 40,000 people respectively, according to the Singapore-based newspaper The Straits Times.

At one affected bank, the threat actor reportedly breached a loan progress inquiry service used by financial brokers. At another bank, the attacker compromised an employee mobile work-support system.

The details of which system was hit at which institution, and how far the data exposure extends, are among the questions CrowdStrike said remain open. The firm did not confirm a final tally of affected organizations.

Regulator Issues a Consumer Alert

South Korea's Financial Services Commission issued a consumer alert relating to the attacks on October 6. The warning urged customers of the hacked companies to be vigilant about potential phishing attacks and loan scams.

The agency added that affected organizations will continue to investigate the extent of the data breaches and provide updates accordingly. That means the picture of who is affected, and by how much, is expected to change as the investigations proceed.

For customers of the named banks, the alert is the most direct official guidance so far on what to watch for in the wake of the reported exfiltration.

Tracking the Actor Through Telegram

CrowdStrike's account says the threat actor asked Claude for help finding Korean Telegram data sales groups, in an apparent effort to sell the stolen information. That detail sits alongside the personal identifiers found in one of the exposed session records.

The Telegram username and Maoming location surfaced in a single Claude Code prompt. CrowdStrike said it is likely those details belong to the person who carried out the ARTEX-related activity, though the firm stopped short of confirming an identity.

The data-sale query and the personal details together form part of the evidence CrowdStrike used to reach its moderate-confidence assessment about the actor's language and motivation. The firm's blog lays out the infrastructure and session artifacts behind that view.

A Multi-Model Setup

The ARTEX instance at the center of the campaign did not rely on a single model. CrowdStrike reported that DeepSeek v4.1-flash served as the primary LLM backend, while GLM-5.3 and Grok 4.6 were used for additional Claude Code sessions.

Claude Code markdown documents and session histories were recovered from the open directories on the attacker-controlled infrastructure, alongside ARTEX configuration files and Claude memory files. CrowdStrike used those artifacts to piece together how the campaign was structured.

The firm's blog describes the activity as an example of AI tooling enabling a financially motivated actor to carry out multiple intrusions within a short time span, and it presents the infrastructure linkage as the thread that connects the individual attacks.

  • Campaign window: late September to early October 2026
  • Breach at Shinhan Bank: 25,000 people affected, per The Straits Times
  • Breach at Yegaram Savings Bank: 40,000 people affected, per The Straits Times
  • South Korea's Financial Services Commission issued its consumer alert on October 6
  • CrowdStrike published its blog on October 7

Open Questions and Unconfirmed Details

CrowdStrike's own account leaves several points unresolved. The firm said the total number of organizations affected remains unconfirmed, and it described its assessment of the actor's identity and motivation as held with moderate confidence rather than certainty.

The reported breaches at Shinhan Bank and Yegaram Savings Bank, including the figures of 25,000 and 40,000 people, come by way of The Straits Times rather than from CrowdStrike's own count. The Financial Services Commission said affected organizations will keep investigating the extent of the breaches and issue updates as they go.

What is documented in the firm's blog is the infrastructure: the single IP address tying the attacks together, the ARTEX instance, the open directories, the Claude Code documents and session histories, the Chinese-language pentesting prompt, and the LLM backends named in the configuration.

Why This Matters to Defenders

The CrowdStrike account describes a campaign in which an attacker used an agentic pentesting tool and several LLM backends to work across multiple targets in a short window. For security teams at financial institutions, the reported pattern suggests that the tooling behind an intrusion may not be a single product to inventory, but a combination of open-source agents and third-party models that an operator can assemble and swap between.

The exposed directories also point to a practical issue: infrastructure left open can itself become evidence. In this case, session histories and configuration files on attacker-controlled addresses are what allowed the researchers to reconstruct the campaign, which suggests that defenders who monitor for exposed directories tied to active intrusions may catch artifacts they would otherwise miss.

For customers of the affected South Korean banks, the Financial Services Commission's warning points to the risk that follows a breach rather than the breach itself. Phishing and loan scams that reference real account or transaction details are harder to dismiss, and the agency has said the affected organizations will keep updating the public as their investigations continue.

This story is currently reported by CrowdStrike and relayed through other outlets, with no independent corroboration of the campaign's full scope yet. The firm's moderate-confidence assessment and its note that the number of affected organizations remains unconfirmed mean the picture could shift as South Korean authorities and the banks release further findings.

#crowdstrike#artex#south korea#ai pentesting#bank breach#llm

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories