What CrowdStrike found
CrowdStrike Intelligence published an analysis on 7 October of a campaign against South Korean financial organisations that ran from late September into early October. The tool at the centre of it is ARTEX, which the firm describes as a recently released open-source agentic penetration testing tool developed in China.
The campaign has not been attributed to a named adversary. CrowdStrike assesses with moderate confidence that the operator is a Chinese speaker and financially motivated, on the basis of the Chinese-developed tooling and Chinese-language prompts. The number of organisations affected remains unconfirmed.
How it was found
Not through a detection. Through an open directory.
The operator ran a two-server setup: a Hong Kong IP as primary infrastructure, and a separate address hosting the ARTEX instance. Analysis of attacker-controlled open directories on the Hong Kong address exposed Claude Code session histories, Claude memory files and ARTEX configuration files, including a Chinese-language pentesting prompt. Nine proxy IPs were used during the ARTEX activity.
The session logs also record the operator asking a model where Korean breach data is typically sold, and for help finding Korean Telegram data-sale groups. One session asked for a security researcher résumé highlighting the ARTEX results. CrowdStrike says the personal details in that prompt likely relate to the operator but cannot be definitively linked.

Which models, and in which role
This matters, because the reporting around it has blurred it. The ARTEX instance ran on DeepSeek v4.1-flash as its primary backend, likely reached through an API proxy and reseller. Claude Code sessions ran alongside, and GLM-5.3 from Zhipu AI and Grok 4.6 appeared in additional sessions.
So this is not one vendor’s model conducting intrusions. It is an open-source agent framework with a cheap Chinese model underneath it and several commercial assistants used around the edges, which is both less dramatic and more difficult to police.
The targets
Per industry reporting CrowdStrike cites, one bank’s loan progress inquiry service used by financial brokers was breached, and another bank’s employee mobile work-support system was compromised. The activity resulted in data exfiltration.

The developer’s response
ARTEX’s developer, identified as Autumn-27, said the attacks had nothing to do with them and that the tool was built for learning and research, to help organisations test security risk within authorised assets, The Hacker News reported. The project “will no longer be updated and will be converted to a closed source”, with no future releases or maintenance.
That closes the repository. It does not retrieve the copies already downloaded, and an agent framework is mostly prompts and orchestration rather than a binary anyone has to update.
What to watch
CrowdStrike’s assessment is that AI tooling let a financially motivated actor run multiple intrusions in a short span, and that adversaries will keep experimenting with it. The testable version of that claim is the interval between intrusions in the next campaign of this shape.