CrowdStrike Intelligence says it found open directories belonging to an unnamed threat actor that held AI coding-agent session histories and configuration files for ARTEX, an open-source agentic penetration-testing tool, tied to a campaign against South Korean financial organizations.

What happened

In a report dated October 7, CrowdStrike says the campaign ran from late September to early October 2026 and resulted in exfiltrated data. It has not attributed the activity to a named adversary. It assesses with moderate confidence that the actor is a Chinese speaker and financially motivated, citing ARTEX, which it describes as developed in China, and Chinese-language prompts.

The report relies on industry reporting for the victims. It says several South Korean financial organizations had data breaches starting in late September, that one bank’s loan progress inquiry service used by financial brokers was breached, and that another bank’s employee mobile work-support system was compromised. CrowdStrike says the number of affected organizations is unconfirmed.

Why it matters

CrowdStrike’s assessment is that the tooling let a financially motivated actor run multiple intrusions in a short span, and that adversaries will likely keep experimenting with AI in their operations. That is one vendor’s reading of one actor’s files, not a measure of how common the approach is. It follows our reporting on the PoeLLM malware that targets exposed AI servers and DIVD’s account of an apparent AI agent breach.

One original point

The detail that helps defenders most is not the AI. The actor left working notes and prompts on servers reachable without authentication, which means the operators of agent tooling face the same exposure problem as everyone else: session logs and memory files hold the target list, the method and the output.

What to do

Financial-sector teams can load CrowdStrike’s indicators into detection and search logs back to late September. The two breached systems it names, a broker-facing inquiry service and an employee work-support system, are worth reviewing on any estate for authentication and exposure.

Source: CrowdStrike Intelligence, October 7, 2026