Back to Intelligence

ARTEX AI and Claude Agents Weaponized Against South Korean Banks: Detecting AI-Orchestrated Intrusion Tooling in Your Environment

SA
Security Arsenal Team
October 10, 2026
10 min read

Earlier this month, South Korea's financial sector was hit by a series of intrusions that, per reporting from BleepingComputer, were orchestrated by a Chinese threat actor wielding two force multipliers that should be on every defender's radar in 2026: the ARTEX AI penetration testing suite and autonomous Claude agents. This is not a hypothetical "AI could be used in attacks someday" story. This is confirmed, in-the-wild operational use of AI-driven offensive tooling against production banking infrastructure.

What makes this campaign significant isn't a novel zero-day — it's the compression of the attack lifecycle. An operator equipped with an AI pentest suite and LLM agents can reconnoiter, enumerate, craft exploits, pivot, and iterate on failed attempts at machine speed, with a fraction of the human labor a traditional intrusion requires. For SOC teams, that means the dwell time you used to have between initial access and lateral movement is shrinking. If your detection strategy still assumes a human-paced adversary, you are already behind.

Financial institutions are the immediate victims here, but the tooling is sector-agnostic. If ARTEX AI and Claude agents work against South Korean banks, they work against your environment. Healthcare, energy, SaaS — the target list will widen as these capabilities proliferate. The time to build detections is now, while the tooling is still identifiable.

Technical Analysis: How AI-Orchestrated Attacks Change the Observable Surface

The Tooling

ARTEX AI penetration testing suite — an AI-augmented offensive framework that automates phases of the kill chain traditionally requiring skilled human operators: target enumeration, vulnerability identification, exploit selection, and post-exploitation tasking. Like Cobalt Strike before it, a dual-use tool in the hands of a hostile actor becomes a standardized adversary platform — which is actually good news for defenders, because standardized tooling has standardized artifacts.

Claude agents — Anthropic's Claude models invoked via API and agentic frameworks (Claude Code, MCP-based tool use) to autonomously execute attack tasks: generating and iterating on exploit code, parsing tool output, writing phishing content, and orchestrating follow-on actions. The operator effectively supervises rather than drives.

The Attack Chain (Defender's View)

Based on the reporting, the intrusion pattern follows an AI-accelerated version of a classic playbook:

  1. Reconnaissance & enumeration — Automated scanning of external banking infrastructure, with AI used to triage results and prioritize attack surface far faster than manual analysis.
  2. Initial access — Exploit attempts against exposed services, with the LLM iterating on payloads in near-real-time when attempts fail.
  3. Foothold & tooling deployment — Offensive framework components staged on compromised hosts.
  4. AI-assisted post-exploitation — Agent-driven command generation, credential access, and lateral movement decisions, with the LLM API in the loop.

What This Means for Detection

No CVE was disclosed in this reporting — the story is the methodology, not a single bug. The defensive opportunity lies in three observable artifacts unique to this class of operation:

  • Offensive tooling artifacts: ARTEX AI components, like any framework, leave process, file, and path indicators.
  • LLM API egress: Agentic attack workflows require callback to model provider API endpoints (e.g., api.anthropic.com) from infrastructure that has zero legitimate business reason to talk to an LLM API — domain controllers, database servers, production banking systems.
  • Machine-speed execution patterns: Bursts of diverse tool execution (enumeration → exploit → credential access) in timeframes no human operator produces.

Exploitation status: Confirmed active exploitation in the wild against South Korean financial institutions. No CISA KEV entry applies (no CVE disclosed). Treat as an active, ongoing TTP shift.

Detection & Response

Sigma Rules

YAML
---
title: ARTEX AI Offensive Suite Execution
description: Detects execution of ARTEX AI penetration testing suite components based on binary names, install paths, and module artifacts associated with the framework observed in attacks on South Korean financial institutions.
references:
  - https://www.bleepingcomputer.com/news/security/hacker-used-artex-ai-and-claude-agents-to-target-south-korean-banks/
  - https://attack.mitre.org/techniques/T1588.002/
author: Security Arsenal
date: 2026/01/22
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|contains:
      - '\artex'
      - '\artexai'
  selection_cli:
    CommandLine|contains:
      - 'artex'
      - 'artex_ai'
      - 'artex-agent'
  condition: 1 of selection_*
falsepositives:
  - Authorized red team engagements using the same suite (verify against approved exercise windows)
level: high
---
title: Claude Agent or MCP Tooling on Non-Developer Hosts
description: Detects execution of Claude CLI, Claude Code agents, or Model Context Protocol (MCP) server processes on systems where AI development tooling is not expected, consistent with LLM-agent-driven intrusion activity.
references:
  - https://www.bleepingcomputer.com/news/security/hacker-used-artex-ai-and-claude-agents-to-target-south-korean-banks/
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/01/22
status: experimental
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    CommandLine|contains:
      - 'claude mcp'
      - 'claude_code'
      - 'claude-code'
      - 'mcp-server'
      - '@anthropic'
      - 'ANTHROPIC_API_KEY'
  filter_known_dev_hosts:
    Computer|contains:
      - '-DEV-'
      - '-WKS-'
  condition: selection and not filter_known_dev_hosts
falsepositives:
  - Developers running approved AI coding assistants on workstations (scope via asset inventory, not just hostname)
level: high
---
title: LLM API DNS Query from Server Infrastructure
description: Detects DNS resolution of AI model provider API endpoints from systems, a strong signal of agentic LLM tooling executing in-environment when baselined against approved AI integrations.
references:
  - https://www.bleepingcomputer.com/news/security/hacker-used-artex-ai-and-claude-agents-to-target-south-korean-banks/
  - https://attack.mitre.org/techniques/T1071.001/
author: Security Arsenal
date: 2026/01/22
status: experimental
logsource:
  category: dns_query
  product: windows
detection:
  selection:
    QueryName|endswith:
      - 'api.anthropic.com'
      - 'claude.ai'
      - 'api.openai.com'
  condition: selection
falsepositives:
  - Approved enterprise AI integrations (baseline and suppress known-good service accounts/hosts)
  - End-user browsing to claude.ai from workstations (tune to server VLANs for high fidelity)
level: medium

KQL Hunt — Microsoft Sentinel / Defender

KQL — Microsoft Sentinel / Defender
// Hunt 1: LLM API egress from servers (agentic attack tooling callback)
// Scope to server assets; any hit here warrants investigation.
let Lookback = 7d;
let ServerDevices = (DeviceInfo
    | where DeviceType has_any ("Server", "DomainController")
    | summarize by DeviceId, DeviceName);
DeviceNetworkEvents
| where TimeGenerated > ago(Lookback)
| where RemoteUrl has_any ("api.anthropic.com", "claude.ai", "api.openai.com")
| join kind=inner ServerDevices on DeviceId
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, AccountName
| order by TimeGenerated desc;

// Hunt 2: ARTEX / Claude agent process artifacts across the estate
let Lookback2 = 14d;
DeviceProcessEvents
| where TimeGenerated > ago(Lookback2)
| where ProcessCommandLine has_any ("artex", "claude mcp", "claude-code", "mcp-server", "ANTHROPIC_API_KEY")
    or FileName has_any ("artex", "claude.exe", "mcp-server")
| project TimeGenerated, DeviceName, FileName, FolderPath, ProcessCommandLine, AccountName, SHA256
| order by TimeGenerated desc;

// Hunt 3: Machine-speed execution bursts — many distinct tools spawned in short windows
// AI-driven operators produce tool diversity no human matches. Tune threshold to your baseline.
let Lookback3 = 7d;
DeviceProcessEvents
| where TimeGenerated > ago(Lookback3)
| where FileName in~ ("nmap.exe", "masscan.exe", "net.exe", "nltest.exe", "whoami.exe", "ipconfig.exe", "systeminfo.exe", "mimikatz.exe", "rubeus.exe", "psexec.exe", "wmic.exe", "certutil.exe")
| summarize DistinctTools = dcount(FileName), Tools = make_set(FileName), FirstCmd = min(TimeGenerated), LastCmd = max(TimeGenerated) by DeviceName, AccountName, bin(TimeGenerated, 5m)
| where DistinctTools >= 6
| project DeviceName, AccountName, WindowStart = FirstCmd, WindowEnd = LastCmd, DistinctTools, Tools
| order by DistinctTools desc;

Velociraptor VQL — Endpoint Forensic Hunt

VQL — Velociraptor
-- Hunt for AI offensive tooling artifacts and LLM API connections across the fleet
-- Deploy as a hunt; triage hosts with hits in either section.

// Section 1: Processes and files matching ARTEX / Claude agent indicators
LET proc_hits = SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)artex|claude[ -]?(code|mcp)|mcp-server|ANTHROPIC_API_KEY'
   OR Exe =~ '(?i)artex|claude'

LET file_hits = SELECT FullPath, Size, Mtime
FROM glob(globs=['C:/Users/*/.claude*/**', 'C:/ProgramData/*artex*/**', 'C:/*artex*/**', '/tmp/*artex*', '/home/*/.claude*/**'], accessor='auto')

// Section 2: Live network connections to LLM API endpoints (resolved IPs vary; catch process context)
LET net_hits = SELECT Pid, Name, Path, RemoteAddr, RemotePort, Status
FROM netstat()
WHERE RemotePort = 443
  AND Name =~ '(?i)python|node|claude|artex'

SELECT * FROM proc_hits

Hardening & Verification Script

PowerShell
# AI-Tooling-Egress-Control.ps1 — Audit and restrict unauthorized AI tooling and LLM API egress
# Run elevated on servers / via GPO or RMM for fleet deployment.
# TEST in a pilot OU before broad enforcement — approved AI integrations will break if not excepted.

$ErrorActionPreference = 'Continue'
$ReportPath = "$env:ProgramData\AIToolingAudit_$(Get-Date -Format yyyyMMdd_HHmmss).log"

# 1. Audit for AI agent tooling artifacts on the host
Write-Output "=== AI Tooling Artifact Audit ===" | Out-File $ReportPath
$suspectPaths = @("$env:USERPROFILE\.claude", "$env:ProgramData\artex", "C:\artex", "$env:TEMP\artex")
foreach ($p in $suspectPaths) {
    if (Test-Path $p) { "FOUND: $p" | Out-File $ReportPath -Append }
}
Get-Process | Where-Object { $_.ProcessName -match 'artex|claude' } |
    Select-Object ProcessName, Id, Path | Out-File $ReportPath -Append

# 2. Check for Anthropic API keys in environment variables (system + user scope)
Write-Output "=== API Key Exposure Check ===" | Out-File $ReportPath -Append
foreach ($scope in 'Machine','User') {
    $key = [Environment]::GetEnvironmentVariable('ANTHROPIC_API_KEY', $scope)
    if ($key) { "WARNING: ANTHROPIC_API_KEY set at $scope scope" | Out-File $ReportPath -Append }
}

# 3. Block egress to LLM API endpoints from this host (remove or scope for approved integrations)
$llmDomains = @('api.anthropic.com', 'claude.ai')
foreach ($d in $llmDomains) {
    $ruleName = "Block-LLM-Egress-$d"
    if (-not (Get-NetFirewallRule -DisplayName $ruleName -ErrorAction SilentlyContinue)) {
        $ips = (Resolve-DnsName $d -ErrorAction SilentlyContinue | Where-Object Type -eq 'A').IPAddress
        foreach ($ip in $ips) {
            New-NetFirewallRule -DisplayName "$ruleName-$ip" -Direction Outbound -Action Block `
                -RemoteAddress $ip -RemotePort 443 -Protocol TCP | Out-Null
        }
        "BLOCKED egress: $d" | Out-File $ReportPath -Append
    }
}

# 4. Verify no unexpected listeners spawned by agent tooling
Write-Output "=== Unexpected Listener Check ===" | Out-File $ReportPath -Append
Get-NetTCPConnection -State Listen | Where-Object { $_.LocalPort -notin 135,139,445,3389,5985,5986 } |
    ForEach-Object { $proc = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
        "$($_.LocalPort) -> $($proc.ProcessName) ($($proc.Path))" } | Out-File $ReportPath -Append

Write-Output "Audit complete: $ReportPath"

Remediation & Defensive Recommendations

  1. Baseline and control LLM API egress. No production server, domain controller, or database host should initiate outbound connections to api.anthropic.com, api.openai.com, or similar model endpoints. Implement default-deny egress policy at the perimeter and allowlist only sanctioned AI integrations through a controlled proxy. This single control severs the callback loop agentic attack tooling depends on.

  2. Inventory authorized AI usage — now. You cannot detect unauthorized Claude agents if you don't know where authorized ones live. Catalog every approved AI assistant, API key, and agent framework in your environment, mapped to owning teams and service accounts. Anything outside that inventory is an incident.

  3. Treat offensive AI suites like Cobalt Strike. ARTEX AI and its peers are dual-use tooling. Add their known artifacts to your EDR blocklists, threat intel feeds, and detection engineering backlog the same way you handled Cobalt Strike beacons in 2017. Require written authorization and exercise windows for any internal red team use.

  4. Compress your response SLAs. AI-accelerated adversaries move between kill chain phases in minutes, not hours. Revisit your triage and containment playbooks: automated isolation on high-confidence detections is no longer optional for financial-sector and critical-infrastructure defenders.

  5. Rotate and audit API keys. Any LLM provider API keys stored on endpoints, in CI/CD pipelines, or in environment variables are theft targets — a stolen key both funds the attacker's operations and masks their traffic as your identity. Audit key usage in your provider consoles for anomalies.

  6. Hunt the behavior, not just the binary. Tool names change; machine-speed execution patterns don't. Deploy temporal-correlation detections (Hunt 3 above) that flag inhuman tool-execution diversity, and pair them with your existing credential-access and lateral-movement analytics.

No vendor patch applies here — this is a TTP evolution, not a product flaw. Monitor BleepingComputer's original reporting and South Korean FSRC/FSC advisories for attributed indicators as they are published, and fold them into the detections above.

Related Resources

Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.