chiprook
← Security
SecurityOctober 8, 2026, 07:26

CrowdStrike: Hackers Used ARTEX and LLMs to Target South Korean Banks

CrowdStrike Intelligence reported that an unattributed threat actor used the ARTEX tool with multiple LLMs (Claude Code, DeepSeek v4.1-flash, GLM-5.3, Grok 4.6) to attack South Korean financial institutions. The campaign resulted in data exfiltration, with attacker infrastructure hosted on a Hong Kong server and IP 38.244.50[.]120.

CrowdStrike: Hackers Used ARTEX and LLMs to Target South Korean Banks
#CrowdStrike#Claude#DeepSeek#Grok
Read next
Security

North Korean hackers stole $10.7M via fake job interviews

Security

North Korean hackers posed as recruiters, infected 30,000 devices

Security

Security agencies warn North Korean hackers target job seekers to steal crypto

Security

Cisco Talos finds CLOSEDQUORUM malware that picks its next move via four LLMs