CrowdStrike: Hackers Used ARTEX and LLMs to Target South Korean Banks
CrowdStrike Intelligence reported that an unattributed threat actor used the ARTEX tool with multiple LLMs (Claude Code, DeepSeek v4.1-flash, GLM-5.3, Grok 4.6) to attack South Korean financial institutions. The campaign resulted in data exfiltration, with attacker infrastructure hosted on a Hong Kong server and IP 38.244.50[.]120.
- Attacks ran through ARTEX with DeepSeek, Claude Code, GLM-5.3 and Grok 4.6 backends
- Attacker infrastructure included a Hong Kong server and node 38.244.50[.]120
- The campaign led to data exfiltration from South Korean financial institutions
- CrowdStrike did not disclose initial access vectors or the scope of impact
Read next
Security