Dev.to Security 🔐 Cybersecurity 👁 0 📖 6 min read

ARTEX: LLM-Integrated Penetration Testing Tool Used to Target South Korean Financial Institutions and Exfiltrate Data

1. Basic Information Article Name: Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance Publisher: CrowdStrike Intelligence Publication Date: 2026-10-07 Original Source: CrowdStrike Intelligen

1. Basic Information

2. Executive Summary

An unidentified threat actor used ARTEX and multiple LLMs to target South Korean financial institutions. CrowdStrike found session histories, configuration files, and memory files in open directories on attacker-controlled infrastructure and reported that the campaign resulted in data exfiltration.

3. Attack Flow

Confirmed Campaign Structure

  1. The attacker managed Claude Code sessions, prompts, and memory on a Hong Kong-based server.
  2. They ran ARTEX on a separate server at 38.244.50[.]120, utilizing LLM backends such as DeepSeek.
  3. They executed operations targeting South Korean financial institutions. Individual initial access vectors remain unconfirmed.
  4. CrowdStrike reported that the campaign resulted in data exfiltration. The scope of impact on individual organizations is unconfirmed.

4. Attacker Positioning and Execution Location

  • The threat actor targets Internet-facing services and business systems of financial institutions from external infrastructure. Methods for acquiring initial credentials and privileges have not been publicly disclosed.

5. Visibility for Victims and Administrators

  • Users: May experience anomalies in business services, unexpected authentication prompts, or unauthorized use of personal and transaction data.
  • Administrators: Indicators include external reconnaissance, suspicious proxies, and heavy data access, downloads, and egress.

6. Success and Failure Conditions

Success Conditions

  • Reaching the target service and gaining access to internal resources via vulnerabilities or unauthorized credentials.
  • Maintaining network connectivity between the infrastructure running ARTEX/LLM tools and the target.

Failure Conditions and Countermeasures

  • Reduce the attack surface of externally exposed services, apply patches, enforce MFA, apply least privilege, and implement egress filtering.
  • Hunt through historical logs using public infrastructure and session artifacts, and revoke compromised accounts and tokens.

7. What Happens Upon Success

  • Data exfiltration from financial institutions.
  • Rapid reconnaissance and continued attacks via AI-assisted workflows.
  • Potential unauthorized access to customer/broker services or employee systems.

8. Observable Logs

The following items are candidates for investigation. ARTEX/LLM API communications and Claude-related files were identified on the attacker's infrastructure; observations in victim environments have not been made public. These should be checked if evidence from the attacker's infrastructure is obtained, while victim environments should focus on investigating communications with listed IPs, request contents, authentication, data access, and outbound transmissions.

  • Email: No email vectors specific to this case have been reported.
  • Proxy / SWG / DNS: In victim environments, verify communications with CrowdStrike-listed IPs, request contents, and outbound transmissions. ARTEX/LLM API communications should be investigated if attacker infrastructure evidence is obtained.
  • Endpoint / EDR: Check for shells/tools launched from web/application processes, credential access, data staging, and archive creation.
  • Identity / IdP: Check for logins from unusual locations, service account usage, and changes to tokens, MFA, or privileges. Investigate subsequent usage even if initial access occurs pre-authentication.
  • SaaS / Cloud: Check cloud WAFs, load balancers, API audits, data access, and bulk exports.
  • Network: Check for scans against targeted services, proxy-routed connections, large outbound transfers, and communications with nodes such as 38.244.50[.]120.

9. Attack Success Determination

Confirmed in Public Information

  • Information Theft or Session Compromise Confirmed: CrowdStrike reported that the campaign produced exfiltrated data. However, details regarding individual organizations, datasets, and initial vectors remain unconfirmed.

Internal Determination Criteria

  • Subsequent Compromise Confirmed: Do not determine that subsequent compromises have succeeded based solely on targeting or shared infrastructure mentioned in public reports. Separately verify successful lateral movement or persistence using host, authentication, and operational logs from each organization.
  • Correlate requests, processes, authentication, data access, and outbound transfers to distinguish between attack attempts and successes.
  • Do not infer successful compromise from HTTP status codes or a single alert alone. Corroborate the assessment with evidence from your own environment.

10. Investigation Playbook

  • Investigation Starting Point: Start with communications involving listed infrastructure, abnormal requests to externally exposed financial services, and heavy data access/egress.
  • Initial Verification: Confirm targeted products/versions, external reachability, exposure duration, authentication conditions, and the timing of applied mitigations and updates.
  • Endpoint / Server Investigation: Check process trees, service logs, file modifications, persistence mechanisms, shell/miner execution, and outbound communications.
  • Authentication / Cloud Investigation: Check for suspicious account/token/API usage, permission changes, unusual connection sources, and resource access.
  • Subsequent Operations: Track post-initial-event credential access, lateral movement, additional downloads, outbound transmissions, and account creation.
  • Containment: Restrict external accessibility and attack paths, preserve evidence, and then apply updates, rotate credentials, and terminate malicious processes.
  • Categorization: Distinguish among reconnaissance/attack attempts, initial execution, successful authentication, information theft, and subsequent compromises.

11. Defense and Detection Ideas

  • Single Events: In victim environments, detect communications with listed IPs or unusual bulk exports. Treat ARTEX artifacts and LLM API usage as traces confirmed on attacker infrastructure.
  • Chronological Correlation: Correlate reconnaissance -> authentication/exploit -> data access -> staging -> egress.
  • Threat Hunting: Search for communications with listed infrastructure since late September, unusual proxies, and anomalous authentication, data access, and egress. Claude/ARTEX files and model API usage should be investigated if evidence from attacker infrastructure is available.
  • Log Limitations: Without prompt history, agent-generated commands cannot be distinguished from manual operations. Prioritize endpoint and network evidence.
  • Prioritized Mitigations: Prioritize patching external services, enforcing MFA, applying least privilege to service accounts, implementing egress filtering, and monitoring exports.

12. Facts / Inference / Hypothesis

Facts

  • CrowdStrike identified infrastructure related to a campaign targeting South Korean financial institutions and reported that it led to data exfiltration.
  • The IP 38.244.50[.]120 hosted an ARTEX instance and an open directory, and another Hong Kong-based IP exposed Claude Code session histories, ARTEX configurations, and Claude memory files.
  • Session histories indicated a two-server configuration using the Hong Kong-based server as the primary infrastructure and 38.244.50[.]120 as the ARTEX server.
  • ARTEX used DeepSeek v4.1-flash as its primary backend, and additional sessions also utilized GLM-5.3 and Grok 4.6.
  • Based on Chinese-language prompts and other indicators, CrowdStrike assessed with moderate confidence that the actor is likely a Chinese-speaking, financially motivated individual or group. This is not an attribution to a named actor.
  • Compromises of individual banks' loan inquiry services and mobile work-support systems originate from industry reporting, and CrowdStrike did not state that it independently verified all details.

Inference

  • Preserving tool sessions, memory, prompts, and operator infrastructure within the same case makes it easier to reconstruct the boundaries between manual operations and LLM-assisted actions.
  • Because the actor can switch between models, a single provider's abuse-prevention controls cannot, on their own, stop the entire operation. Detection should focus on network, identity, and endpoint evidence.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Unresolved Items and Further Investigation."

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1588.007 Obtain Capabilities: Artificial Intelligence high Used ARTEX and multiple LLMs in offensive operations.
T1090 Proxy medium CrowdStrike presented proxy infrastructure overlapping with the campaign. Utilization scope at each intrusion stage remains unconfirmed.

14. Unresolved Items and Further Investigation

  • The exact number of affected financial institutions, initial intrusion vectors for each organization, compromise duration, and acquired data.
  • The boundaries between actions autonomously executed by ARTEX and those directly instructed and executed by the operator.
  • Confirmed group attribution for the attacker and attribution evidence beyond Chinese-language prompts.

15. Impact on SOCs and Organizations

Financial institutions and brokerage services operating similar externally exposed applications or mobile work-support systems should use the campaign targeting South Korean institutions to review their defenses. Rather than relying solely on AI tool names or model providers as detection criteria, monitor external reconnaissance, authentication, data access, and exfiltration as continuous events, and preserve agent sessions, memory, and prompts if evidence from attacker infrastructure becomes available.

16. Summary by Target Audience

  • For SOCs: Correlate listed infrastructure, continuous operations against externally exposed services, data staging, and egress. ARTEX-related files should be verified if evidence from attacker infrastructure is obtained.
  • For Administrators: Review inventories of externally exposed financial services and business support systems, MFA, service accounts, egress rules, and sensitive data access.
  • For Users: Report unexpected authentication requests or business system anomalies, and do not approve unverified MFA requests.
📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.