For the complete documentation index, see /llms.txt. Markdown version of this page: /en/insights/ai-security/crowdstrike-artex-south-korean-finance.md.
AI Security ↗

CrowdStrike finds ARTEX in attacks on South Korean finance

Open-source testing software and AI models appear in a real intrusion campaign.

AI-generated illustration of a desktop monitor with the CrowdStrike logo and a diagram connecting an AI model, security tools and financial systems.
AI-generated editorial concept. The screen is an illustration, not CrowdStrike product UI or evidence from the attacks.

In brief: CrowdStrike reports AI tooling in attacks against South Korean financial organisations.

Its 7 October investigation links ARTEX, an open-source penetration-testing tool, to activity that exposed data. Researchers recovered session histories and configuration files from attacker infrastructure.

Penetration testing means looking for weaknesses by attempting to exploit them. With the system owner’s permission, it is security work. Without that permission, the same activity can be an intrusion.

What does an AI model do in an attack?

A model can suggest an action, but software must execute it. In an agent, the model can choose a tool, read its result and decide what to do next. Anthropic’s explanation of agents describes this repeated cycle of decisions and feedback.

For example, a tool might check whether a service responds. Its result goes back to the model, which chooses the next step. This is a general illustration of how agents work, not a reconstruction of this campaign.

That differs from someone asking a chatbot for an explanation and manually carrying out every step. It also leaves room for a person to set the goal, intervene or change direction.

What the findings tell us

The report does not establish fully autonomous attacks or a confirmed victim count.

For a Norwegian business reading this news, the useful distinction is between evidence of AI use and proof of what AI accomplished independently. An investigation can establish the first without establishing the second. Treating them as interchangeable makes the threat harder to understand.

Our AI hacking explanation explores that distinction in more detail.

← Back to all insights
Questions or inquiry? [email protected] Contact us →