Skip to content

InvestNot yet confirmed elsewhere1 publisher2 min readPublished

Attacker used free Chinese pentest agent and four LLMs in South Korean bank intrusions

A single actor used a free Chinese pentest agent and four commercial AI models to breach South Korean financial firms in about two weeks. The free, resold toolkit let one person breach several firms at once, and researchers expect adversaries to keep using it to lift their tempo.

The Investor · Invest desk

How we use AISend a correction

Illustration accompanying Attacker used free Chinese pentest agent and four LLMs in South Korean bank intrusions
Generated illustration

What happened

  • At one bank the operator breached a loan progress inquiry service used by financial brokers, and at another an employee mobile work-support system was compromised, with the total number of affected firms still unconfirmed.
  • The operation ran on two servers, a Hong Kong address as primary infrastructure and one hosting the ARTEX instance, behind nine proxy IP addresses.
  • Session logs show the actor asking Claude where Korean breach data is sold and for Korean Telegram groups that trade it.

Why it matters

  • cost The attack kit was free to acquire and its model access was likely resold, so an intruder's input cost stays low while banks still carry the fixed cost of monitoring broker and employee systems.
  • capability A single operator can now run intrusions across several firms at once.
  • precedent Researchers expect adversaries to keep using this tooling to raise operational tempo, so banks should treat agentic intrusion attempts as recurring.
  • constraint The entry points were broker-facing and employee mobile services, so hardening core banking alone does not close the path these intrusions used.

ARTEX is open-source and recently released, so acquiring it cost the operator nothing [3]. The model it leaned on, DeepSeek v4.1-flash, was likely reached through an LLM API proxy or reseller rather than a direct contract, and the same operator ran Zhipu AI's GLM-5.3 and Grok 4.6 inside Claude Code sessions and queried Claude directly [9][10][4]. That is four models, one free agent, two servers and nine proxy IP addresses [20][3][8][11]. The report does not give costs for any of it.

From late September to early October 2026, roughly two weeks, that setup breached a broker loan progress service at one bank and an employee mobile work-support system at another, and the researchers have not confirmed how many firms in total [2][19][5][6][7].

The other reading is less alarming, and the same evidence carries it. Researchers reconstructed the whole operation from open directories the attacker left exposed, including Claude Code session histories, ARTEX configuration files and Claude memory files [4]. Leaving those open was careless. One session even carried personal details, submitted alongside a request for a resume presenting the campaign's results, that the researchers think probably belong to the attacker though they cannot confirm it [15]. Read that way, the campaign looks less like an industrial operation and more like one person building a portfolio.

The session logs also show the actor asking Claude where threat actors sell Korean breach data and for help finding Korean Telegram groups that trade it [12]. The campaign exfiltrated data, and those records have somewhere to go after the intrusion ends [1].

The campaign has not been pinned to a named adversary, and the researchers hold only moderate confidence that the actor is a financially motivated Chinese speaker, inferred from ARTEX and the Chinese-language prompts [13][14]. They expect adversaries to keep experimenting with this tooling to lift their operational tempo [18]. In my view the cost argument survives even if this operator was sloppy. The tool is free and the models are commodity. Nothing in the method required the mistakes that exposed it. It fails only if ARTEX's hits depended on specific unpatched broker-facing systems, and the report names the services it reached, not the vulnerabilities it used [17].

What to watch

  • Whether more South Korean financial firms disclose breaches, giving a confirmed count beyond the two services named.
  • Whether ARTEX or similar open-source agentic pentest tools turn up in campaigns outside Korea.
  • Whether model providers or the API resellers act on the proxy and reseller access the operation relied on.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence45
Adoption15
Hype gap+15
Incentives
Insufficient
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    A threat intelligence report said a campaign against South Korean financial organisations resulted in exfiltrated data.

    ReportedSupportedSource: The Paypers, citing a threat intelligence reportView cited source
  2. [2]

    The activity ran from late September to early October 2026.

    ReportedSupportedSource: The Paypers, citing a threat intelligence reportView cited source
  3. [3]

    The campaign combined ARTEX, a recently released open-source agentic penetration testing tool developed in China, with several large language models.

    ReportedSupportedSource: The Paypers, citing a threat intelligence reportView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thepaypers.com

    1 article · October 9, 2026

    ARTEX agentic tool used in attacks on South Korean finance firms

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories