CrowdStrike: unknown actor used AI-driven ARTEX pentest tool against South Korean finance
rohanpaul_ai · x · 2026-10-09
CrowdStrike published a report on an unknown threat actor using ARTEX, a recently released Chinese open-source agentic pentesting tool, to target South Korean finance:
- The attacker's own Claude Code session histories, memory files and ARTEX configurations were left in open directories, letting CrowdStrike reconstruct the full AI-assisted intrusion chain.
- At least 7 South Korean financial institutions were affected; the model access was likely obtained through an API reseller.
- One of the first AI-assisted intrusion campaigns with full forensic traces — highly relevant for AI security research.
More from Safety
- We're putting too much faith in AI's ability to say no — nordicinst · 2026-10-09
- MIT Tech Review: We're putting too much faith in AI's ability to say no — MIT Tech Review AI · 2026-10-09
- 'Dystopian': Co-op latest firm to put staff under AI surveillance — marigo · 2026-10-09
- Anthropic's first policy update in over a year bans sustained cruelty toward Claude — AlexTensor · 2026-10-09
- OpenAI exposes Russian and Iranian ops that planted fake stories in real news outlets — The Decoder · 2026-10-09
- Ex-UK AISI comms officer goes independent and questions why AI companies don't act on their own warnings — AaronBergman18 · 2026-10-09