Skip to content
Security & Trust

Exposed files show AI tools used against South Korean financial firms

CrowdStrike read the attacker's own AI logs. They show one open-source tool, several AI models and a short timeline.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Exposed files show AI tools used against South Korean financial firms
In brief
  • CrowdStrike read an attacker's exposed AI session logs from a campaign against South Korean financial organizations. They show an open-source tool driving several AI models.
  • It is one actor and one campaign, so it documents a pace of attack rather than proving a wider trend.
  • Leaders should ask which partner- and staff-facing systems are tested, and how often, and whether any control assumes a single AI provider.

The attacker's workbench was left open

Most intrusion stories are rebuilt from what victims find afterward. This one is rebuilt from what the attacker left behind.

CrowdStrike Intelligence found open directories on servers tied to a campaign against South Korean financial organizations. An open directory is a server folder that anyone can browse. The folders held logs of the attacker's work with Claude Code, setup files for a tool called ARTEX, and Claude memory files.

That gave CrowdStrike a direct view of how the attacker worked. One threat actor used an open-source tool alongside several AI models. CrowdStrike says this let a money-driven actor run multiple intrusions in a short time. The same logs show the actor asking Claude where Korean breach data is sold.

What CrowdStrike found, and what remains unknown

CrowdStrike says the campaign ran from late September to early October 2026. It says the campaign led to stolen data.

CrowdStrike also points to industry reports of breaches at several South Korean financial firms. Those reports say the attacker got into a loan-status service used by brokers at one bank. At another bank, they say, an employee mobile work-support system was compromised.

Several points remain open. The number of affected organizations is unconfirmed. CrowdStrike has not tied the activity to a named adversary.

It does offer a view, with moderate confidence. The actor is likely a Chinese speaker who wants money. That view rests on a Chinese-developed tool and Chinese-language prompts.

2
Servers in the attacker's setup
Source: CrowdStrike Intelligence (October 7, 2026)

How the toolkit worked

ARTEX is a recently released open-source tool developed in China. CrowdStrike calls it an agentic penetration testing tool.

Penetration testing means simulating an attack to find weaknesses. Defenders normally do it. "Agentic" means the AI takes steps on its own instead of only answering questions.

The logs show a setup with two servers. One, based in Hong Kong, was the attacker's main base. The other, at 38.244.50[.]120, hosted the ARTEX instance that likely carried out the Korean attacks.

The second server's open folder held a file called CLAUDE.md. It contained a Chinese-language prompt telling the AI how to run its testing. Think of it as a standing instruction sheet for the AI.

No single model did all the work. DeepSeek v4.1-flash was the primary model behind ARTEX. The actor added GLM-5.3 and Grok 4.6 for additional Claude Code sessions.

CrowdStrike says the actor likely reached DeepSeek through xcai[.]pro. It describes that site as a likely reseller of API access.

What this one case shows

CrowdStrike reads the case as an example of AI helping a profit-driven actor hit several targets quickly. This is one campaign by one actor. It documents that pace. It does not prove a wider trend.

What follows is our interpretation, not CrowdStrike's finding. The actor mixed one open-source tool with several AI models. A control that assumes attackers rely on one AI provider would cover only part of that setup. CrowdStrike does not report that any safeguard failed.

Where the risk may sit

The reported targets were a broker-facing service and an employee mobile system. The source does not say what data was taken. It does not say how the attacker got in.

Our interpretation is that systems like these may be tested less often than a firm's main website. That is a question for your own inventory. It is not a finding from this report.

Late September to early October 2026
Activity window
Source: CrowdStrike Intelligence (October 7, 2026)

Questions to put to your team

First, ask the security team to check logs against the indicators in CrowdStrike's report. These include 38.244.50[.]120 and xcai[.]pro.

Second, ask for a list of every service that outside partners or staff phones can reach. Ask when each was last tested, and by whom.

Third, ask whether your own testing uses agentic tools. If attackers use them, a once-a-year manual test may measure a different pace.

Fourth, check whether any control assumes attackers use one AI provider.

The exposure here was an open folder. The lasting question is how often your partner and staff systems get tested compared with your main website.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CrowdStrike.

Share this insight