CrowdStrike has uncovered infrastructure, AI session histories and configuration files connected to the recent cyberattacks against South Korean financial institutions.
The security company assesses with moderate confidence that the unidentified attacker is a Chinese speaker motivated by financial gain. Evidence found in exposed AI coding sessions suggests the individual may be 26 years old and based in Maoming, Guangdong, China.
These details represent an investigative assessment, not a confirmed identification. CrowdStrike said the information likely belongs to the attacker but cannot definitively connect it to the person who conducted the intrusions.
ATTACKER USED ARTEX WITH MULTIPLE AI MODELS
CrowdStrike said the campaign combined conventional offensive tools with ARTEX, an open-source agentic penetration-testing platform developed in China.
ARTEX does not contain its own large language model. It connects to external models that can help automate vulnerability discovery and testing. The attacker’s installation reportedly used DeepSeek v4.1-flash as its primary model and supplemented it with GLM-5.3 and Grok 4.6.
CrowdStrike also recovered Claude Code session histories and memory files from threat-actor infrastructure. The sessions showed the attacker using Chinese-language prompts to direct penetration-testing activity.
ARTEX’s developers state that the software is intended for personal learning, code research and authorized local testing—not attacks against real online systems.
OPEN INFRASTRUCTURE EXPOSED THE ATTACKER’S OPERATIONS
CrowdStrike traced the activity through an ARTEX server at 38.244.50[.]120 and additional infrastructure hosted in Hong Kong.
Open directories on these systems exposed:
- ARTEX configuration files
- Claude Code session histories
- Claude memory files
- Chinese-language penetration-testing instructions
- Proxy addresses used during the campaign
- Information about organizations targeted by the attacker
The records showed a two-server arrangement. One system hosted the ARTEX installation believed to have supported the attacks, while the Hong Kong infrastructure served as the attacker’s primary operational environment.
This exposure gave investigators unusual visibility into how a financially motivated attacker incorporated agentic AI into real intrusion activity.
AI SESSIONS REVEALED POSSIBLE PERSONAL DETAILS
One Claude Code session involved a request to create a cybersecurity researcher résumé that included accomplishments associated with the ARTEX campaign.
The prompt contained a name represented by the initials “YY,” a telephone number, a Telegram username, educational information, an age and a location in Guangdong.
The same Telegram username appeared in sessions involving research against an NFT marketplace and a possible Chinese payment platform.
Reuters contacted the telephone number identified in CrowdStrike’s research. The person who answered denied knowledge of the attacks. No authority has publicly confirmed the suspect’s identity, and the activity has not been attributed to a named cybercriminal or state-sponsored group.

