CrowdStrike has disclosed a campaign in which a Chinese-speaking threat actor deployed ARTEX, an agentic AI penetration testing framework, alongside Anthropic's Claude large language model to accelerate intrusions against South Korean financial institutions. This is not a hypothetical future threat — it is a live, observed operational pattern where the attacker offloaded reconnaissance, exploitation planning, and post-compromise tasking to autonomous AI tooling, compressing the intrusion timeline from weeks to hours.
Financial sector defenders, and frankly any SOC operating in 2026, need to treat this as a milestone event: the barrier to running a competent, multi-stage intrusion has dropped. What previously required a skilled red team operator can now be orchestrated by a mid-tier actor with an agentic framework and an LLM subscription. Your detection surface hasn't changed — but your detection tempo requirements have.
No CVE is associated with this campaign in the reporting. This is a technique-driven threat (MITRE ATT&CK techniques amplified by AI orchestration), not a vulnerability-driven one. That distinction matters: you cannot patch this away. You must hunt it.
Technical Analysis
What Happened
According to CrowdStrike's analysis, a Chinese-speaking intrusion actor targeted South Korean financial services organizations using two AI capabilities in tandem:
- ARTEX (agentic penetration testing tool) — an autonomous/agentic offensive framework capable of planning and executing pentest-style kill chain steps: target reconnaissance, attack surface enumeration, exploit selection, payload generation, and iterative post-exploitation actions. Agentic tools like ARTEX chain LLM reasoning to tool execution (shell commands, scanners, exploit frameworks) with minimal human oversight.
- Claude (Anthropic LLM) — used by the actor to assist with data breach operations: likely scripting, payload refinement, translating/decrypting exfiltrated data, writing phishing lures in native-quality Korean, and troubleshooting intrusion obstacles in real time.
Attack Chain (Defender's View)
From observed agentic-AI-assisted intrusions, the operational pattern typically looks like this:
- Initial access via spear-phishing or exploitation of exposed edge services (LLM-assisted lure generation dramatically improves phishing quality in the victim's language — Korean in this case).
- Automated reconnaissance executed by the agentic framework: rapid internal scanning, AD enumeration (
nltest,net group,ldapsearch, BloodHound-style collection), and service fingerprinting at machine speed. - Iterative exploitation — the agent reasons over scan output, selects exploits, generates payloads, and retries with variations when attempts fail. Expect unusual velocity and variety: many distinct payloads and command patterns in a short window.
- Data staging and exfiltration — Claude-assisted parsing and summarization of stolen data, compression/archive staging, and exfil over HTTPS or cloud storage.
Key Behavioral Indicators of Agentic-AI-Assisted Intrusions
Veteran SOC analysts should watch for the operational signature, not a specific hash:
- High-velocity enumeration: complete internal recon in minutes-to-hours rather than days.
- Enumerating tools run from unexpected processes: recon commands spawned from non-standard parents (script interpreters, office apps, or unknown binaries in user-writable directories).
- Outbound HTTPS to LLM API endpoints (
api.anthropic.com,api.openai.com) from servers, DMZ hosts, or workstations with no legitimate business use of AI APIs. Compromised hosts are increasingly used as proxies for attacker AI queries. - Rapid payload iteration: multiple distinct script/binary names with short lifespans in temp or user profile directories (
%TEMP%,%APPDATA%,/tmp,/dev/shm). - Native-language phishing with unusually high grammatical quality targeting financial staff.
Exploitation Status
This is confirmed active exploitation in the wild per CrowdStrike's attribution. No CVE applies; this is a TTP-level threat. There is no CISA KEV entry — the mitigation is detection engineering and egress control, not patching.
Detection & Response
Sigma Rules
The rules below target the observable behaviors of this campaign type: machine-speed enumeration bursts, suspicious outbound AI API traffic from endpoints, and rapid disposable-payload execution from user-writable paths. Tune the allowlists to your environment before deployment.
---
title: Rapid Internal Enumeration Burst - Potential Agentic AI Recon
id: 3f9c2a71-4b6d-4e58-a91c-7d2e5f8a0b11
status: experimental
description: Detects bursts of internal reconnaissance commands executed in short succession from a single host, consistent with agentic AI frameworks (e.g., ARTEX) performing automated enumeration at machine speed.
references:
- https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
- https://attack.mitre.org/techniques/T1087/
- https://attack.mitre.org/techniques/T1018/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.discovery
- attack.t1087
- attack.t1018
- attack.t1482
logsource:
category: process_creation
product: windows
detection:
selection_img:
Image|endswith:
- '\nltest.exe'
- '\net.exe'
- '\net1.exe'
- '\dsquery.exe'
- '\adfind.exe'
- '\sharpHound.exe'
- '\bloodhound.exe'
selection_cli:
CommandLine|contains:
- ' /domain_trusts'
- 'domain admins'
- 'enterprise admins'
- 'dsquery computer'
- 'dsquery user'
- '-CollectionMethod'
condition: selection_img or selection_cli
falsepositives:
- Legitimate IT administration and inventory scripts - baseline admin workstations and exclude known service accounts
level: high
---
title: Outbound Connection to LLM API Endpoint from Server or Endpoint
id: 8b1e4d92-5c7f-4a39-b62d-9e3a1f5c7d22
status: experimental
description: Detects network connections to commercial LLM API endpoints (Anthropic, OpenAI) initiated by non-browser processes. Threat actors have abused Claude and other LLMs during intrusions for payload generation and data processing; unexpected API egress may indicate attacker tooling or use of a compromised host as an AI proxy.
references:
- https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
- https://attack.mitre.org/techniques/T1102/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.command_and_control
- attack.t1102
- attack.exfiltration
logsource:
category: network_connection
product: windows
detection:
selection_dst:
DestinationHostname|contains:
- 'api.anthropic.com'
- 'api.openai.com'
filter_browser:
Image|endswith:
- '\chrome.exe'
- '\msedge.exe'
- '\firefox.exe'
- '\brave.exe'
condition: selection_dst and not filter_browser
falsepositives:
- Approved internal AI integrations and developer tooling - maintain an allowlist of sanctioned AI application paths
level: medium
---
title: Short-Lived Script or Binary Execution from User-Writable Directory
id: c5d7f0a3-2e8b-4c46-9d71-4a2b6e8f0c33
status: experimental
description: Detects execution of scripts and binaries from temp and user-profile directories with randomized-looking filenames, a pattern consistent with agentic frameworks rapidly generating and discarding payloads during iterative exploitation.
references:
- https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
- https://attack.mitre.org/techniques/T1059/
- https://attack.mitre.org/techniques/T1204/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059
- attack.defense_evasion
logsource:
category: process_creation
product: windows
detection:
selection_path:
Image|contains:
- '\AppData\Local\Temp\'
- '\AppData\Roaming\'
- '\Users\Public\'
selection_random:
Image|re: '\\[a-z0-9]{8,12}\.(exe|bat|ps1|py|js)$'
condition: selection_path and selection_random
falsepositives:
- Software installers and auto-updaters - correlate with known installer parent processes and signer metadata
level: medium
KQL — Microsoft Sentinel / Defender
This hunt query correlates two behaviors seen in this campaign: (1) enumeration bursts on a device and (2) non-browser egress to LLM API endpoints. Run the recon-burst hunt at 15-minute granularity — agentic recon completes fast, and hourly aggregation will bury the signal.
// Hunt 1: Recon burst - many distinct discovery commands from one device in 15 min
let reconCmds = dynamic(["nltest", "net group", "net localgroup", "dsquery", "adfind", "whoami /all", "ipconfig /all", "arp -a", "route print", "netstat -an"]);
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where reconCmds has (ProcessCommandLine)
| summarize DistinctCmds = dcount(ProcessCommandLine), CmdList = make_set(ProcessCommandLine, 20) by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 15m)
| where DistinctCmds >= 5
| order by DistinctCmds desc;
// Hunt 2: Non-browser process egress to LLM API endpoints
let llmDomains = dynamic(["api.anthropic.com", "api.openai.com", "claude.ai"]);
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any (llmDomains)
| where InitiatingProcessFileName !in~ ("chrome.exe", "msedge.exe", "firefox.exe", "brave.exe", "Teams.exe", "slack.exe")
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
| order by FirstSeen asc;
// Hunt 3: Short-lived executables in user-writable paths (Sysmon Event 1 via SecurityEvent not applicable; use Defender)
DeviceProcessEvents
| where TimeGenerated > ago(3d)
| where FolderPath has_any ("\\AppData\\Local\\Temp\\", "\\AppData\\Roaming\\", "\\Users\\Public\\")
| where FileName matches regex @"^[a-z0-9]{8,12}\.(exe|bat|ps1|py|js)$"
| summarize ExecCount = count(), Parents = make_set(InitiatingProcessFileName) by DeviceName, FileName, FolderPath, SHA256
| order by ExecCount desc;
Velociraptor VQL
Use this artifact to hunt endpoints for the disposable-payload pattern and non-browser processes holding connections to LLM infrastructure — both strong leads when you suspect an agentic-assisted intrusion on a host.
-- Hunt: Disposable payloads in user-writable paths + LLM API connections
-- Payload artifacts in temp/profile directories
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['C:/Users/*/AppData/Local/Temp/*.exe',
'C:/Users/*/AppData/Local/Temp/*.ps1',
'C:/Users/*/AppData/Roaming/*.exe',
'C:/Users/Public/*.exe'])
WHERE Mtime > now() - 604800
ORDER BY Mtime DESC
-- Live connections to LLM API infrastructure
SELECT Pid, Name, Path, Address.Family as Family,
Address.IP as RemoteIP, Address.Port as RemotePort, Status
FROM netstat()
WHERE Status =~ 'ESTABLISHED'
AND Name !~ '(chrome|msedge|firefox|brave|slack|Teams)'
Note: Velociraptor's netstat() resolves IPs, not hostnames — cross-reference RemoteIP against known Anthropic/OpenAI published IP ranges or resolve via your DNS logs (query api.anthropic.com in your DNS analytics for a cleaner retro hunt).
Remediation / Hardening Script
This PowerShell script establishes two controls relevant to this threat: (1) DNS/firewall egress policy verification for LLM API endpoints on hosts with no sanctioned AI use, and (2) an audit of user-writable directories for unsigned executables. Run as Administrator.
# ============================================================
# AI-Augmented Intrusion Hardening & Audit Script
# Targets: LLM API egress control + disposable payload artifacts
# ============================================================
# --- 1. Test whether LLM API egress is reachable from this host ---
$llmEndpoints = @('api.anthropic.com','api.openai.com')
Write-Host "[*] Testing egress to LLM API endpoints..." -ForegroundColor Cyan
foreach ($ep in $llmEndpoints) {
$result = Test-NetConnection -ComputerName $ep -Port 443 -WarningAction SilentlyContinue
if ($result.TcpTestSucceeded) {
Write-Host "[WARN] $ep is REACHABLE on 443. If no sanctioned AI workload exists on this host, block at the egress firewall/proxy." -ForegroundColor Yellow
} else {
Write-Host "[OK] $ep is blocked/unreachable." -ForegroundColor Green
}
}
# --- 2. Add Windows Defender Firewall block rules for LLM API egress (optional, review first) ---
# Resolve and block at IP level as a compensating control; prefer DNS sinkholing at the resolver
foreach ($ep in $llmEndpoints) {
$ips = (Resolve-DnsName $ep -Type A -ErrorAction SilentlyContinue | Where-Object {$_.IPAddress}).IPAddress
foreach ($ip in $ips) {
$ruleName = "Block-LLM-Egress-$ep-$ip"
if (-not (Get-NetFirewallRule -DisplayName $ruleName -ErrorAction SilentlyContinue)) {
New-NetFirewallRule -DisplayName $ruleName -Direction Outbound -Action Block `
-RemoteAddress $ip -Protocol TCP -RemotePort 443 -Profile Any | Out-Null
Write-Host "[+] Created firewall rule: $ruleName" -ForegroundColor Green
}
}
}
# --- 3. Audit user-writable directories for unsigned executables (last 7 days) ---
$paths = @("$env:SystemDrive\Users\*\AppData\Local\Temp",
"$env:SystemDrive\Users\*\AppData\Roaming",
"$env:SystemDrive\Users\Public")
$cutoff = (Get-Date).AddDays(-7)
Write-Host "[*] Scanning for unsigned executables in user-writable paths..." -ForegroundColor Cyan
$findings = foreach ($p in $paths) {
Get-ChildItem -Path $p -Include *.exe,*.ps1,*.bat,*.js,*.py -Recurse -ErrorAction SilentlyContinue |
Where-Object { $_.LastWriteTime -gt $cutoff } |
ForEach-Object {
$sig = Get-AuthenticodeSignature $_.FullName
[PSCustomObject]@{
Path = $_.FullName
Modified = $_.LastWriteTime
Signature = $sig.Status
Signer = $sig.SignerCertificate.Subject
}
}
}
$unsigned = $findings | Where-Object { $_.Signature -ne 'Valid' }
if ($unsigned) {
Write-Host "[ALERT] $($unsigned.Count) unsigned/invalid files found:" -ForegroundColor Red
$unsigned | Format-Table -AutoSize
$unsigned | Export-Csv -Path ".\unsigned_payload_audit_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
} else {
Write-Host "[OK] No unsigned executables found in scope." -ForegroundColor Green
}
Remediation
There is no patch for this campaign — the remediation is architectural and procedural. Prioritize the following:
- Egress control for LLM APIs. Inventory which hosts have a legitimate business need to reach
api.anthropic.com,api.openai.com, and similar endpoints. Block or proxy all others. Log and alert on any non-sanctioned connection. This is now as fundamental as blocking known-bad C2. - Compress your detection tempo. Agentic recon completes in minutes. Detection rules aggregated at 24-hour batch intervals are useless here. Move discovery-burst detection (KQL above, 15-minute windows) to near-real-time analytics rules in Sentinel with automated host isolation playbooks.
- Harden financial-sector identity infrastructure. South Korean financial firms were the target; global banking peers should assume targeting. Enforce phishing-resistant MFA (FIDO2) for all remote access, and monitor for LLM-polished Korean/English spear-phishing — expect grammatically flawless lures referencing real internal projects.
- Application control on user-writable paths. Enforce WDAC or AppLocker rules blocking execution from
%TEMP%,%APPDATA%, andC:\Users\Public. Agentic frameworks depend on being able to drop and run disposable tooling. - Threat-hunt retroactively. Search the last 90 days of DNS and proxy logs for LLM API domains from server subnets and DMZ hosts. A compromised host used as an AI proxy is a quiet, high-confidence intrusion indicator.
- Update IR playbooks. Add "AI-assisted intrusion" as a scenario: shortened dwell time assumptions, higher payload variety, and the possibility that exfiltrated data is being summarized/processed through an attacker-controlled LLM session (relevant for legal/regulatory breach assessment in financial jurisdictions).
- Follow vendor research. Monitor CrowdStrike's threat research portal and Anthropic's threat-intelligence reporting for IOC and account-level disruption updates as this attribution matures.
The Bottom Line
The significance of the CrowdStrike disclosure isn't that AI was used — it's that an agentic framework ran a coordinated intrusion against hardened financial targets with a single operator. Your adversary's marginal cost of sophistication just dropped to near zero. Defenders who respond by tightening egress, accelerating detection windows, and hunting for machine-speed behavior will absorb this shift. Defenders still operating on dwell-time assumptions from 2023 will not.
Related Resources
Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.