
CrowdStrike finds ARTEX AI and Claude Code in attacks on banks
The security firm assesses with moderate confidence that a Chinese-speaking attacker used AI agents; the banks have not confirmed the tool.
Security firm CrowdStrike found traces of ARTEX AI and Claude Code sessions on servers used by the attacker who hit South Korean banks. It published the findings on Oct. 7. ARTEX AI is an open-source tool of Chinese origin that puts artificial intelligence agents to work on penetration testing, meaning simulated attacks used to find weaknesses.
In open directories on one server, analysts saw the history of the Claude Code sessions, the ARTEX configuration and Claude memory files. According to BleepingComputer, the attacker also asked Claude to suggest Telegram groups where stolen Korean data is sold. The report does not say which provider served those sessions, and BleepingComputer's story includes no response from Anthropic.
CrowdStrike does not tie the campaign to a named group. It says, with "moderate confidence," that the actor probably speaks Chinese and is financially motivated. The ARTEX instance used DeepSeek v4.1-flash as its main model.
The banks' own reports, according to Korea JoongAng Daily, are narrower:
| Institution | Data exposed |
|---|---|
| Shinhan Bank | More than 25 000 customers |
| KB Kookmin Bank | 119 customers |
| Hana Bank | 89 customers |
| BNK Financial Group | 11 cases |
Woori Bank and NH Nonghyup Bank faced similar attacks but reported no data leaks. At Shinhan, the access was to a service used only by loan brokers.
The authorities respond
On Oct. 2, South Korea's Financial Services Commission called an emergency meeting and ordered a security review across the sector. It asked institutions to list IT assets reachable from the internet, including AI systems, and to check for paths that give access to internal information without authentication. Its secretary general, Shin Jin-chang, said institutions must be "fully prepared" to limit harm to consumers after an incident.
Several points remain unconfirmed. Neither any bank nor the commission has said publicly that ARTEX was behind every intrusion. That link comes from CrowdStrike and press reports. CrowdStrike also does not specify what data was taken or how many organizations were affected. BleepingComputer adds that ARTEX's author decided to close the source code and stop releasing versions, but derivative copies in English and Korean already exist.



