Between late September and early October 2026, an actor with suspected Chinese ties used the open-source AI agent ARTEX to chain together DeepSeek V4.1-Flash, GLM-5.3, Grok 4.6 and Anthropic Claude Code in attacks on at least seven South Korean financial institutions, exposing data including the annual income and loan limits of 68,000 customers.
What Happened
According to an October 7 report from CrowdStrike, the campaign lasted roughly two weeks. Shinhan Bank confirmed that information on about 25,000 customers was leaked, while KB Kookmin Bank and Hana Bank reported 119 and 89 affected customers respectively. Tallies in the South Korean media indicate that more than 67,000 people across the seven institutions may have been affected. The attackers left behind Claude Code session histories, ARTEX configuration files and Chinese-language instruction files on one piece of infrastructure.
Investigators found two servers, one in Hong Kong and another running an ARTEX instance. ARTEX used DeepSeek V4.1-Flash as its primary backend while calling GLM-5.3 and Grok 4.6 in separate Claude Code sessions. Targets included a loan progress inquiry service and an employee mobile work support system.
How It Worked
ARTEX is not a standalone language model but an open-source agentic penetration-testing tool. It can combine automated penetration-testing workflows with general-purpose AI models to achieve multi-model coordination. The report says the attackers used Chinese-language prompt files to direct the AI through penetration steps, pairing proxy addresses with existing infrastructure to complete the intrusions. After the incident came to light, the developer "Autumn" (Li Puhua) moved the project from open source to closed source and stopped updating it.
The tool lets operators rapidly integrate the outputs of different models and shorten the cycle from reconnaissance to data acquisition. CrowdStrike's assessment indicates that such agentic tools supported multiple targeted operations against financial systems within a short period.
Industry Impact
South Korea's Financial Services Commission has discussed relaxing network isolation rules so that institutions can bring in external AI security services more quickly. The National Assembly's Policy Affairs Committee plans to summon the heads of five major commercial banks for questioning on October 19. Financial Services Commission Chairman Lee Eog-weon acknowledged that the initial response was inadequate and noted the need to fight AI-driven attacks with AI.
The incident laid bare the financial system's defensive gaps in the face of AI-assisted penetration. Internal services at multiple banks were breached, showing that traditional isolation measures offer limited protection against agentic tools.
Strategic Assessment
[Analysis] The operational use of multi-model coordinated agentic tools shows that a single-model defense strategy is no longer enough to counter combined attacks. Financial institutions need to reassess the balance between adopting AI tools and maintaining network isolation, or similar incidents could recur in other regions. The developer's swift move to closed source also reflects a community trust crisis for open-source security tools once they are abused.
[Analysis] CrowdStrike identifies the operators as Chinese speakers with an economic motive but does not point to a specific organization. This low-attribution, high-efficiency attack model may push global security vendors to accelerate work on detection capabilities for agentic tools.
© 2026 Winzheng.com 赢政天下 | 转载请注明来源并附原文链接