high Claude Code · AI Security

Open directories exposed an attacker's Claude Code sessions: how ARTEX was used against Korean financial firms

Data graphic: a red EXPOSED, open server stamp beside the headline Attacker's Claude Code logs sat open. CrowdStrike reports an unknown actor ran the ARTEX pentest tool against South Korean finance.
NS

Identity security analyst · Published Oct 11, 2026, 4:33 PM EDT

CrowdStrike says an unnamed actor ran ARTEX and Claude Code against South Korean finance, and left session logs open. What defenders can hunt for.

CrowdStrike says an unnamed, likely Chinese-speaking and financially motivated actor ran the open-source agentic pentest tool ARTEX, plus Claude Code, against South Korean financial organisations in late September and early October 2026. Open directories on the actor's servers exposed Claude Code session histories, a CLAUDE.md prompt file, memory files and ARTEX configuration. That makes this a rare first-hand look at an attacker's AI agent workflow. Anthropic was not compromised; Claude Code was a tool the actor ran.

What happened

CrowdStrike Intelligence published its findings on 2026-10-07. It describes ARTEX as "a recently released open-source agentic penetration testing (pentesting) tool developed in China". The activity resulted in exfiltrated data, but CrowdStrike says "the number of organizations affected remains unconfirmed". Its post names no victim and gives no customer counts.

CrowdStrike links ARTEX to the intrusions through industry reporting (it cites Kyunghyang Shinmun): references to the string ARTEX in HTML files on a reportedly actor-controlled server, and overlapping IP addresses across several victims. CrowdStrike does not describe how the actor got in. The Korean press does.

Entry points and method (Kyunghyang Shinmun, 2026-10-04). The paper links two systems to named banks: Shinhan Bank's loan-progress inquiry service used by brokers, and KB Kookmin Bank's internal mobile work-support system for employees. It says the attack is presumed to be AI-automated brute force: random values were entered to find valid customer numbers, and contact and financial details were then pulled. Stealien CEO Park Chan-am told the paper that the banks' main systems had authentication beyond IDs and passwords, but peripheral systems lacked comparable defences. That is a press account, not a CrowdStrike finding.

Victims and counts (reported, not confirmed by CrowdStrike). Kyunghyang reports 25,727 items of personal information for Shinhan, 119 customers for KB Kookmin and 89 for Hana Bank. It also names BNK Busan Bank, Yegaram Savings Bank, Hyundai Capital and Welcome Savings Bank (2,200+ corporate customer records), plus two P2P investment companies. Reuters, in a wire story dated 2026-10-09 carried by Claims Journal and Taipei Times (one source, not two), attributes the Shinhan and KB Kookmin counts to the banks themselves and says at least nine banks "have disclosed or been reported" as targets. Reuters also reported a police probe and a call by President Lee Jae Myung for a robust response.

Timeline (Kyunghyang). ARTEX appeared on GitHub on 26 July and its latest version on 24 September. The attack on KB Kookmin began on 27 September, with intrusions across institutions from 27 to 30 September. Financial authorities held an emergency inspection meeting on 4 October. The Financial Security Institute found the attack IPs almost the same across banks; IPs from eight countries, including South Korea, the US, Japan and Hong Kong, were reportedly used.

The tool's author. Kyunghyang says ARTEX was developed by GitHub user "Autumn-27" and was spotted through an HTML page title reading "autonomous penetration test console" in Chinese. Outlets including OODAloop report the developer then made ARTEX closed source and halted public updates. We could not read the developer's notice ourselves. Copies already downloaded keep working, so the closure does not remove the tool.

Why it matters

The workflow is the story. CrowdStrike's SVP Adam Meyers said on a call with reporters, as Reuters quotes him: "this is significant because it allows one human to target many customers in a very short period of time using the power of AI." An agentic tool that plans and runs recon and exploitation steps from a prompt file lowers the effort per target (we covered another attacker-run agent, the CARBONATO botnet), and the open directories show what that looks like in practice, not in a vendor demo.

It also shows the limits of what the evidence proves. CrowdStrike calls the actor unattributed. Its assessment, made with moderate confidence, is that the actor is "likely a Chinese speaker and financially motivated", based on the Chinese-developed ARTEX and observed Chinese-language prompts. It is not a named group, and nothing here ties the activity to a state.

Technical details

Two servers. CrowdStrike describes a Hong Kong-based IP as primary actor infrastructure (the post does not publish its address). Analysis of it found open directories holding Claude Code session histories, ARTEX configuration files and Claude memory files. A second IP, 38.244.50[.]120, hosted an ARTEX instance that CrowdStrike says was "likely responsible for the described Korean attacks". On that host an open directory served a Claude Code instruction file at http[:]//38.244.50[.]120:18899/.claude/CLAUDE.md, a Chinese-language pentest prompt telling the model how to conduct testing.

Models. The ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend. The actor added GLM-5.3 (Zhipu AI) and Grok 4.6 "for additional Claude Code sessions". CrowdStrike says DeepSeek was likely reached through an LLM API proxy or reseller, xcai[.]pro. The post does not say how Claude Code was pointed at non-Anthropic models, and we do not infer it.

Operator prompts. In the sessions the actor asked Claude where threat actors typically sell Korean breach data and for help finding Korean Telegram data-sales groups. In one session the actor asked for a security-researcher résumé with bullets on ARTEX results; the prompt carried personal details (an initial, an age of 26, and a location in Maoming, Guangdong). CrowdStrike says currently available information "cannot definitively associate these details with the threat actor", and one handle in them also appeared in unrelated sessions. We do not reproduce them. Reuters described the suspect more firmly as a "likely China-based 26-year-old"; the primary source is more cautious, and we follow it.

Indicators (defanged as published).

  • Actor-controlled IP: 38.244.50[.]120
  • Nine proxy IPs seen in Claude Code sessions during ARTEX activity: 101.53.80[.]20, 205.214.59[.]31, 124.155.252[.]63, 154.201.79[.]246, 23.248.249[.]90, 23.158.220[.]98, 103.248.148[.]84, 203.160.133[.]172, 209.209.85[.]38
  • Likely LLM proxy/reseller domain: xcai[.]pro

CrowdStrike maps the activity to MITRE ATT&CK T1583.003 (Acquire Infrastructure: VPS), T1588.007 (Obtain Capabilities: Artificial Intelligence) and T1090 (Proxy).

What defenders should do

CrowdStrike's post publishes indicators and an ATT&CK mapping but no detection rules or mitigations. The steps below are ThreatFrontier's inference, not CrowdStrike guidance.

  • Hunt the indicators. Search proxy, firewall, VPN and web logs from mid-September onward for the ten IPs. The nine proxies are likely rotating exit points, so a miss does not clear you; treat a hit as a lead to scope, not proof.
  • Rate-limit and alert on enumeration of broker- and staff-facing apps. The reported method was guessing valid customer numbers. Alert on sequential or random ID lookups from one source, many distinct IDs with few successes, and a lookup followed by a contact-detail fetch.
  • Put MFA on the side systems. Press accounts say the peripheral systems were protected by ID and password only. Loan-inquiry portals, mobile work-support tools and credit-assessment apps deserve the same controls as core banking. Return the minimum fields per lookup, not full contact records.
  • Don't rely on IPs alone. IPs from eight countries were reportedly used across banks, so block lists age fast; behaviour (machine-speed varied requests) is the more durable signal.
  • Watch for LLM-API egress. Outbound traffic from servers to model APIs or resellers such as xcai[.]pro is unusual for most production hosts and worth an alert.
  • Your own agents. The actor's leak was an exposed web server directory. Make sure .claude directories, session logs and memory files on your own hosts are not served by any web server.

What is still unclear

  • Which organisations were breached, and how many. CrowdStrike says the count is unconfirmed. Kyunghyang lists seven banks and lenders plus two P2P firms; Reuters says at least nine banks. Each is stated as that outlet gives it.
  • Whether the brute-force method is what happened. Kyunghyang says "presumed"; CrowdStrike does not describe initial access.
  • The actor's identity. No named adversary, and the personal details in prompts are unconfirmed.
  • Any Anthropic response. Reuters said Anthropic did not respond to requests for comment, and we found no statement. We found none from DeepSeek, Zhipu AI or xAI either.

Sources

Keep reading

All latest →
  1. highAI SecurityPlugin4Shell: A Pinned Commit SHA Didn't Stop Repo Owners Swapping Plugin Code in Claude Code, Codex, Copilot and Gemini CLI6 min
  2. watchResearchClaude Code vs Codex CLI vs Antigravity CLI vs OpenCode: Coding Agents Compared (2026)15 min
  3. watchResearchClaude Pro vs Max for Claude Code: Is $20 Enough After Opus 5.5?15 min
  4. watchResearchClaude Code Pricing & Token Economics: Subscription vs. Pay-As-You-Go API9 min
  5. watchAI SecurityHow Claude Code Works Internally: From CLI Startup to Agentic Tool Execution13 min
  6. highAI Securityx64dbg MCP plugin shipped an unauthenticated debugger on every network interface (CVE-2026-107824)6 min