The Information Machine
Updated today·New·first covered 9 Oct 2026·4 sources

The ARTEX South Korean bank breach

The gist

CrowdStrike Details ARTEX-Powered Breach of 7 South Korean Banks

A freely available agentic AI pentesting tool was used to breach multiple financial institutions, demonstrating that such tools can lower the barrier to financially motivated intrusions. The attacker's operational failures provided unusually detailed forensic evidence of how the AI-assisted campaign was run.

The full picture

CrowdStrike and South Korean investigators have documented an attack on at least seven South Korean financial firms using ARTEX, a Chinese open-source agentic pentesting tool, with personal data on 68,000 people compromised. The attacker is believed to be a student at South China University of Technology. ARTEX was created by Chinese cybersecurity engineer Li Puhua, also known as 'Autumn', and has been freely downloadable on GitHub since July; it won a Baidu-hosted attack-and-defense competition in September. The attacker's stack included ARTEX running on DeepSeek v4.1-Flash via an API reseller, along with GLM-5.3, Grok 4.6, and Claude Code. CrowdStrike identified an ARTEX instance at IP address 38.244.50[.]120 port 18899, which hosted an open directory containing a CLAUDE.md file with a Chinese-language pentesting prompt specifying how the LLM should conduct penetration testing. A Hong Kong-based IP address appeared within that configuration document. Investigators identified ARTEX's involvement by finding its HTML tag signature in command-and-control server headers. The attacker was caught due to operational failures: they left directory listing enabled on their server, exposing Claude Code session histories, Claude memory files, and ARTEX configurations. Within those sessions, the attacker had asked Claude to add the bank hack to their résumé, providing investigators with personal information, and had also queried Claude about where stolen South Korean data could be sold. South Korean cybersecurity firm Genians' security center head Moon Jong-hyun publicly disclosed the findings on LinkedIn.

How it developed
9 October 2026

CrowdStrike's October 9 blog tied ARTEX, a Chinese open-source pentesting tool by Li Puhua ('Autumn') on GitHub since July, to a breach of at least seven South Korean financial institutions, 68,000 people's data compromised.

Investigators traced ARTEX by its HTML tag signature in C2 server headers and found an exposed CLAUDE.md with a Chinese-language pentesting prompt. The attacker, believed to be a South China University of Technology student, was caught after leaving directory listing enabled, exposing Claude Code sessions where they asked the AI to add the hack to their résumé.

Sources
The daily email

Want this in your inbox?

I send one email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free