Security

An AI hacking tool hit Korean banks, and the attacker left their chat logs open

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • CrowdStrike says a campaign from late September to early October used ARTEX, an open-source agentic pentesting tool developed in China, to steal data from South Korean financial firms.
  • The attacker's open directories exposed Claude Code session histories, memory files and ARTEX configs, which is how the campaign was found.
  • ARTEX's developer has taken the project closed source and stopped updates.
  • A separate AI-driven credential stuffing platform, SCARLET LOOP, tested 12.3 million stolen logins and found 11,832 that worked.

The AI-powered cyberattack everyone has been warning about turned up this month in South Korea. It worked. And it was caught because the attacker was sloppy with their own AI.

What happened

According to CrowdStrike Intelligence, an unattributed operator ran a campaign against South Korean financial organisations from late September to early October 2026, and data was exfiltrated. Reporting in Korea and by The Hacker News names Shinhan Bank and Yegaram Savings Bank among the targets.

The main weapon was ARTEX, an open-source "agentic" penetration testing system built by a developer called Autumn-27. Think of it as a team of AI agents that scan, probe and try exploits without a human driving every step. In this case ARTEX ran on DeepSeek v4.1-flash as its main model, with Z.ai's GLM-5.3 and Grok 4.6 filling in.

CrowdStrike reckons the operator is probably Chinese-speaking and motivated by money, but has not tied them to any known group.

How they got caught

CrowdStrike found open directories on a Hong Kong IP address that exposed the attacker's Claude Code session histories, Claude memory files and ARTEX configuration files. In other words, the attacker's working notes were sitting on the internet.

Those sessions show the operator asking Claude where Korean breach data is typically sold and for help finding Korean Telegram groups that trade it. One prompt referenced a Telegram handle that also appears in unrelated vulnerability research, though CrowdStrike is careful to say that is not proof of identity.

There is a lesson here for defenders too. AI agents leave a much richer trail than a human with a terminal: prompts, plans, memory, configs. Attackers who forget that are handing investigators a diary.

The tool goes dark

Autumn-27 has responded by taking ARTEX closed source and ending updates, saying the tool was built for authorised testing and research. That will not put it back in the box. Forks and copies of open-source security tools tend to live forever.

It is not just one campaign

The same week, Brazilian firm ZenoX published research on SCARLET LOOP, a Portuguese-speaking crew running an AI-driven account takeover platform. It uses one model to find login pages, another to rank targets, and a browser agent with 46 automation tools to log in with stolen credentials while dodging bot detection. Of 12,277,358 credentials tested, 11,832 worked across 3,968 domains. Loyalty, rewards and gift card platforms were the main targets.

The clever part is cost control. Once the agent has cracked a login form, SCARLET LOOP drops the AI and replays the steps cheaply. Intelligence is paid for once per target.

So what

Neither campaign needed a novel exploit. They needed scale and patience, which is exactly what AI agents provide. For banks, that means watching for automated, high-tempo probing that adapts. For everyone else, it means password reuse is now being tested by machines that never get bored. Our AI agent security checklist is a good place to start if you run agents yourself, and a password manager plus a hardware key such as the YubiKey 5C NFC closes off most of what SCARLET LOOP relies on.

This article contains an affiliate link. If you buy through it, Future Technology may earn a small commission at no extra cost to you.

More from Future Technology