CrowdStrike identifies AI tool ARTEX in campaign against South Korean financial organizations

CrowdStrike Intelligence says a campaign against South Korean financial organizations, active from late September to early October 2026, resulted in exfiltrated data. It says the threat actor, likely a financially motivated Chinese speaker (moderate confidence), used ARTEX, an open-source agentic pentesting tool developed in China. The number of affected organizations remains unconfirmed.
NoteCrowdStrike says this activity shows how AI tooling can let a financially motivated actor run multiple intrusions in a short time span, and expects adversaries to keep experimenting with it. For bank security teams in Asia, that is a concrete case to read against their own exposure.
Read the original
The Morning Note, by email
The AI-in-finance stories that matter, before work
One short email each morning, readable in under three minutes. Free, and you can leave anytime.