AI-Powered Pentest Tool Used to Breach South Korean Banks

Infrastructure for a targeted campaign against South Korean financial institutions has been identified. This campaign, active between late September and early October of this year, was determined to result in exfiltrated data.
CrowdStrike Intelligence identified and analyzed the campaign, discovering session histories for Claude Code, Claude memory files, and ARTEX configuration files, enabling direct insight into the threat actor’s operations and tools.
According to the threat intelligence, the agentic AI tooling used alongside conventional offensive capabilities emphasizes an observed, evolving trend in adversarial tradecraft: leveraging penetration testing tools alongside large language models (LLMs) for attacks.
The activity has not yet been associated with a named threat actor. The research suggests the adversary is Chinese-speaking and financially motivated.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!






