A threat intelligence report has detailed a campaign against South Korean financial organisations that resulted in exfiltrated data. The activity ran from late September to early October 2026. It combined ARTEX, a recently released open-source agentic penetration testing tool developed in China, with several large language models (LLMs). The findings draw on open directories controlled by the threat actor, which exposed Claude Code session histories, ARTEX configuration files and Claude memory files. These materials offer a direct view of how the attacker organised and ran its operations.
Breaches at bank-facing services
Industry reports show that several South Korean financial organisations experienced data breaches beginning in late September 2026. At one bank, the attacker reportedly breached a loan progress inquiry service used by financial brokers. At another, an employee mobile work-support system was compromised. The total number of affected organisations has not been confirmed.
Activity across multiple organisations reportedly involved overlapping IP addresses. References to ARTEX were also found in HTML files on a server reportedly under the attacker’s control.
A two-server set-up and multiple models
Researchers linked the IP address 38.244.50[.]120 to the activity. The address hosted an ARTEX instance and an open directory containing a Claude Code markdown file with a Chinese-language prompt that told the LLM how to conduct penetration testing. The file also referenced a Hong Kong-based IP address controlled by the attacker, and that address led analysts to further open directories.
The session histories point to a two-server architecture. The Hong Kong-based address served as the primary infrastructure, while 38.244.50[.]120 hosted the ARTEX instance likely responsible for the attacks. ARTEX relied on DeepSeek v4.1-flash as its primary LLM backend, likely accessed through an LLM API proxy or reseller. The attacker used Zhipu AI’s GLM-5.3 and Grok 4.6 in additional Claude Code sessions. Researchers also identified nine proxy IP addresses used during the operation.
The actor’s activity extended beyond intrusion. Session records show requests to Claude about where threat actors typically sell Korean breach data and for help locating Korean Telegram groups that trade such data.
Attribution and outlook
The campaign has not been attributed to a named adversary. Researchers assess with moderate confidence that the actor is likely a Chinese speaker and financially motivated, based on the use of ARTEX and the Chinese-language prompts. One session contained personal details submitted while the user requested a résumé presenting the campaign’s results. The researchers consider these details likely to belong to the attacker but state they cannot be definitively linked. The same Telegram username appeared in sessions researching vulnerabilities in a Telegram-based NFT gift marketplace. It also appeared in activity against a possible Chinese payment platform.
For the financial sector, the case shows how AI tooling can allow a single financially motivated actor to carry out multiple intrusions within a short period. The targeted systems included broker-facing and employee mobile services rather than only core banking infrastructure. The researchers expect adversaries to keep experimenting with AI tooling to increase their operational tempo and capabilities. Indicators of compromise have been published alongside MITRE ATT&CK mappings covering infrastructure acquisition, the acquisition of AI capabilities and the use of proxies.