Back to Intelligence

Chinese Threat Actor Weaponized ARTEX Agentic Pentesting Tool and Claude AI Against South Korean Banks — Detection and Defense Guide

SA
Security Arsenal Team
October 9, 2026
11 min read

CrowdStrike has disclosed a campaign in which a Chinese-speaking threat actor deployed ARTEX, an agentic AI penetration testing framework, alongside Anthropic's Claude large language model to accelerate intrusions against South Korean financial institutions. This is not a hypothetical future threat — it is a live, observed operational pattern where the attacker offloaded reconnaissance, exploitation planning, and post-compromise tasking to autonomous AI tooling, compressing the intrusion timeline from weeks to hours.

Financial sector defenders, and frankly any SOC operating in 2026, need to treat this as a milestone event: the barrier to running a competent, multi-stage intrusion has dropped. What previously required a skilled red team operator can now be orchestrated by a mid-tier actor with an agentic framework and an LLM subscription. Your detection surface hasn't changed — but your detection tempo requirements have.

No CVE is associated with this campaign in the reporting. This is a technique-driven threat (MITRE ATT&CK techniques amplified by AI orchestration), not a vulnerability-driven one. That distinction matters: you cannot patch this away. You must hunt it.

Technical Analysis

What Happened

According to CrowdStrike's analysis, a Chinese-speaking intrusion actor targeted South Korean financial services organizations using two AI capabilities in tandem:

  1. ARTEX (agentic penetration testing tool) — an autonomous/agentic offensive framework capable of planning and executing pentest-style kill chain steps: target reconnaissance, attack surface enumeration, exploit selection, payload generation, and iterative post-exploitation actions. Agentic tools like ARTEX chain LLM reasoning to tool execution (shell commands, scanners, exploit frameworks) with minimal human oversight.
  2. Claude (Anthropic LLM) — used by the actor to assist with data breach operations: likely scripting, payload refinement, translating/decrypting exfiltrated data, writing phishing lures in native-quality Korean, and troubleshooting intrusion obstacles in real time.

Attack Chain (Defender's View)

From observed agentic-AI-assisted intrusions, the operational pattern typically looks like this:

  • Initial access via spear-phishing or exploitation of exposed edge services (LLM-assisted lure generation dramatically improves phishing quality in the victim's language — Korean in this case).
  • Automated reconnaissance executed by the agentic framework: rapid internal scanning, AD enumeration (nltest, net group, ldapsearch, BloodHound-style collection), and service fingerprinting at machine speed.
  • Iterative exploitation — the agent reasons over scan output, selects exploits, generates payloads, and retries with variations when attempts fail. Expect unusual velocity and variety: many distinct payloads and command patterns in a short window.
  • Data staging and exfiltration — Claude-assisted parsing and summarization of stolen data, compression/archive staging, and exfil over HTTPS or cloud storage.

Key Behavioral Indicators of Agentic-AI-Assisted Intrusions

Veteran SOC analysts should watch for the operational signature, not a specific hash:

  • High-velocity enumeration: complete internal recon in minutes-to-hours rather than days.
  • Enumerating tools run from unexpected processes: recon commands spawned from non-standard parents (script interpreters, office apps, or unknown binaries in user-writable directories).
  • Outbound HTTPS to LLM API endpoints (api.anthropic.com, api.openai.com) from servers, DMZ hosts, or workstations with no legitimate business use of AI APIs. Compromised hosts are increasingly used as proxies for attacker AI queries.
  • Rapid payload iteration: multiple distinct script/binary names with short lifespans in temp or user profile directories (%TEMP%, %APPDATA%, /tmp, /dev/shm).
  • Native-language phishing with unusually high grammatical quality targeting financial staff.

Exploitation Status

This is confirmed active exploitation in the wild per CrowdStrike's attribution. No CVE applies; this is a TTP-level threat. There is no CISA KEV entry — the mitigation is detection engineering and egress control, not patching.

Detection & Response

Sigma Rules

The rules below target the observable behaviors of this campaign type: machine-speed enumeration bursts, suspicious outbound AI API traffic from endpoints, and rapid disposable-payload execution from user-writable paths. Tune the allowlists to your environment before deployment.

YAML
---
title: Rapid Internal Enumeration Burst - Potential Agentic AI Recon
id: 3f9c2a71-4b6d-4e58-a91c-7d2e5f8a0b11
status: experimental
description: Detects bursts of internal reconnaissance commands executed in short succession from a single host, consistent with agentic AI frameworks (e.g., ARTEX) performing automated enumeration at machine speed.
references:
  - https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
  - https://attack.mitre.org/techniques/T1087/
  - https://attack.mitre.org/techniques/T1018/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.discovery
  - attack.t1087
  - attack.t1018
  - attack.t1482
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    Image|endswith:
      - '\nltest.exe'
      - '\net.exe'
      - '\net1.exe'
      - '\dsquery.exe'
      - '\adfind.exe'
      - '\sharpHound.exe'
      - '\bloodhound.exe'
  selection_cli:
    CommandLine|contains:
      - ' /domain_trusts'
      - 'domain admins'
      - 'enterprise admins'
      - 'dsquery computer'
      - 'dsquery user'
      - '-CollectionMethod'
  condition: selection_img or selection_cli
falsepositives:
  - Legitimate IT administration and inventory scripts - baseline admin workstations and exclude known service accounts
level: high
---
title: Outbound Connection to LLM API Endpoint from Server or Endpoint
id: 8b1e4d92-5c7f-4a39-b62d-9e3a1f5c7d22
status: experimental
description: Detects network connections to commercial LLM API endpoints (Anthropic, OpenAI) initiated by non-browser processes. Threat actors have abused Claude and other LLMs during intrusions for payload generation and data processing; unexpected API egress may indicate attacker tooling or use of a compromised host as an AI proxy.
references:
  - https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
  - https://attack.mitre.org/techniques/T1102/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1102
  - attack.exfiltration
logsource:
  category: network_connection
  product: windows
detection:
  selection_dst:
    DestinationHostname|contains:
      - 'api.anthropic.com'
      - 'api.openai.com'
  filter_browser:
    Image|endswith:
      - '\chrome.exe'
      - '\msedge.exe'
      - '\firefox.exe'
      - '\brave.exe'
  condition: selection_dst and not filter_browser
falsepositives:
  - Approved internal AI integrations and developer tooling - maintain an allowlist of sanctioned AI application paths
level: medium
---
title: Short-Lived Script or Binary Execution from User-Writable Directory
id: c5d7f0a3-2e8b-4c46-9d71-4a2b6e8f0c33
status: experimental
description: Detects execution of scripts and binaries from temp and user-profile directories with randomized-looking filenames, a pattern consistent with agentic frameworks rapidly generating and discarding payloads during iterative exploitation.
references:
  - https://www.infosecurity-magazine.com/news/chinese-hacker-ai-korean-banks/
  - https://attack.mitre.org/techniques/T1059/
  - https://attack.mitre.org/techniques/T1204/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059
  - attack.defense_evasion
logsource:
  category: process_creation
  product: windows
detection:
  selection_path:
    Image|contains:
      - '\AppData\Local\Temp\'
      - '\AppData\Roaming\'
      - '\Users\Public\'
  selection_random:
    Image|re: '\\[a-z0-9]{8,12}\.(exe|bat|ps1|py|js)$'
  condition: selection_path and selection_random
falsepositives:
  - Software installers and auto-updaters - correlate with known installer parent processes and signer metadata
level: medium

KQL — Microsoft Sentinel / Defender

This hunt query correlates two behaviors seen in this campaign: (1) enumeration bursts on a device and (2) non-browser egress to LLM API endpoints. Run the recon-burst hunt at 15-minute granularity — agentic recon completes fast, and hourly aggregation will bury the signal.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Recon burst - many distinct discovery commands from one device in 15 min
let reconCmds = dynamic(["nltest", "net group", "net localgroup", "dsquery", "adfind", "whoami /all", "ipconfig /all", "arp -a", "route print", "netstat -an"]);
DeviceProcessEvents
| where TimeGenerated > ago(7d)
| where reconCmds has (ProcessCommandLine)
| summarize DistinctCmds = dcount(ProcessCommandLine), CmdList = make_set(ProcessCommandLine, 20) by DeviceName, InitiatingProcessAccountName, bin(TimeGenerated, 15m)
| where DistinctCmds >= 5
| order by DistinctCmds desc;

// Hunt 2: Non-browser process egress to LLM API endpoints
let llmDomains = dynamic(["api.anthropic.com", "api.openai.com", "claude.ai"]);
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where RemoteUrl has_any (llmDomains)
| where InitiatingProcessFileName !in~ ("chrome.exe", "msedge.exe", "firefox.exe", "brave.exe", "Teams.exe", "slack.exe")
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl
| order by FirstSeen asc;

// Hunt 3: Short-lived executables in user-writable paths (Sysmon Event 1 via SecurityEvent not applicable; use Defender)
DeviceProcessEvents
| where TimeGenerated > ago(3d)
| where FolderPath has_any ("\\AppData\\Local\\Temp\\", "\\AppData\\Roaming\\", "\\Users\\Public\\")
| where FileName matches regex @"^[a-z0-9]{8,12}\.(exe|bat|ps1|py|js)$"
| summarize ExecCount = count(), Parents = make_set(InitiatingProcessFileName) by DeviceName, FileName, FolderPath, SHA256
| order by ExecCount desc;

Velociraptor VQL

Use this artifact to hunt endpoints for the disposable-payload pattern and non-browser processes holding connections to LLM infrastructure — both strong leads when you suspect an agentic-assisted intrusion on a host.

VQL — Velociraptor
-- Hunt: Disposable payloads in user-writable paths + LLM API connections
-- Payload artifacts in temp/profile directories
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['C:/Users/*/AppData/Local/Temp/*.exe',
                 'C:/Users/*/AppData/Local/Temp/*.ps1',
                 'C:/Users/*/AppData/Roaming/*.exe',
                 'C:/Users/Public/*.exe'])
WHERE Mtime > now() - 604800
ORDER BY Mtime DESC

-- Live connections to LLM API infrastructure
SELECT Pid, Name, Path, Address.Family as Family,
       Address.IP as RemoteIP, Address.Port as RemotePort, Status
FROM netstat()
WHERE Status =~ 'ESTABLISHED'
  AND Name !~ '(chrome|msedge|firefox|brave|slack|Teams)'

Note: Velociraptor's netstat() resolves IPs, not hostnames — cross-reference RemoteIP against known Anthropic/OpenAI published IP ranges or resolve via your DNS logs (query api.anthropic.com in your DNS analytics for a cleaner retro hunt).

Remediation / Hardening Script

This PowerShell script establishes two controls relevant to this threat: (1) DNS/firewall egress policy verification for LLM API endpoints on hosts with no sanctioned AI use, and (2) an audit of user-writable directories for unsigned executables. Run as Administrator.

PowerShell
# ============================================================
# AI-Augmented Intrusion Hardening & Audit Script
# Targets: LLM API egress control + disposable payload artifacts
# ============================================================

# --- 1. Test whether LLM API egress is reachable from this host ---
$llmEndpoints = @('api.anthropic.com','api.openai.com')
Write-Host "[*] Testing egress to LLM API endpoints..." -ForegroundColor Cyan
foreach ($ep in $llmEndpoints) {
    $result = Test-NetConnection -ComputerName $ep -Port 443 -WarningAction SilentlyContinue
    if ($result.TcpTestSucceeded) {
        Write-Host "[WARN] $ep is REACHABLE on 443. If no sanctioned AI workload exists on this host, block at the egress firewall/proxy." -ForegroundColor Yellow
    } else {
        Write-Host "[OK]   $ep is blocked/unreachable." -ForegroundColor Green
    }
}

# --- 2. Add Windows Defender Firewall block rules for LLM API egress (optional, review first) ---
# Resolve and block at IP level as a compensating control; prefer DNS sinkholing at the resolver
foreach ($ep in $llmEndpoints) {
    $ips = (Resolve-DnsName $ep -Type A -ErrorAction SilentlyContinue | Where-Object {$_.IPAddress}).IPAddress
    foreach ($ip in $ips) {
        $ruleName = "Block-LLM-Egress-$ep-$ip"
        if (-not (Get-NetFirewallRule -DisplayName $ruleName -ErrorAction SilentlyContinue)) {
            New-NetFirewallRule -DisplayName $ruleName -Direction Outbound -Action Block `
                -RemoteAddress $ip -Protocol TCP -RemotePort 443 -Profile Any | Out-Null
            Write-Host "[+] Created firewall rule: $ruleName" -ForegroundColor Green
        }
    }
}

# --- 3. Audit user-writable directories for unsigned executables (last 7 days) ---
$paths = @("$env:SystemDrive\Users\*\AppData\Local\Temp",
           "$env:SystemDrive\Users\*\AppData\Roaming",
           "$env:SystemDrive\Users\Public")
$cutoff = (Get-Date).AddDays(-7)
Write-Host "[*] Scanning for unsigned executables in user-writable paths..." -ForegroundColor Cyan
$findings = foreach ($p in $paths) {
    Get-ChildItem -Path $p -Include *.exe,*.ps1,*.bat,*.js,*.py -Recurse -ErrorAction SilentlyContinue |
        Where-Object { $_.LastWriteTime -gt $cutoff } |
        ForEach-Object {
            $sig = Get-AuthenticodeSignature $_.FullName
            [PSCustomObject]@{
                Path      = $_.FullName
                Modified  = $_.LastWriteTime
                Signature = $sig.Status
                Signer    = $sig.SignerCertificate.Subject
            }
        }
}
$unsigned = $findings | Where-Object { $_.Signature -ne 'Valid' }
if ($unsigned) {
    Write-Host "[ALERT] $($unsigned.Count) unsigned/invalid files found:" -ForegroundColor Red
    $unsigned | Format-Table -AutoSize
    $unsigned | Export-Csv -Path ".\unsigned_payload_audit_$(Get-Date -Format yyyyMMdd).csv" -NoTypeInformation
} else {
    Write-Host "[OK] No unsigned executables found in scope." -ForegroundColor Green
}

Remediation

There is no patch for this campaign — the remediation is architectural and procedural. Prioritize the following:

  1. Egress control for LLM APIs. Inventory which hosts have a legitimate business need to reach api.anthropic.com, api.openai.com, and similar endpoints. Block or proxy all others. Log and alert on any non-sanctioned connection. This is now as fundamental as blocking known-bad C2.
  2. Compress your detection tempo. Agentic recon completes in minutes. Detection rules aggregated at 24-hour batch intervals are useless here. Move discovery-burst detection (KQL above, 15-minute windows) to near-real-time analytics rules in Sentinel with automated host isolation playbooks.
  3. Harden financial-sector identity infrastructure. South Korean financial firms were the target; global banking peers should assume targeting. Enforce phishing-resistant MFA (FIDO2) for all remote access, and monitor for LLM-polished Korean/English spear-phishing — expect grammatically flawless lures referencing real internal projects.
  4. Application control on user-writable paths. Enforce WDAC or AppLocker rules blocking execution from %TEMP%, %APPDATA%, and C:\Users\Public. Agentic frameworks depend on being able to drop and run disposable tooling.
  5. Threat-hunt retroactively. Search the last 90 days of DNS and proxy logs for LLM API domains from server subnets and DMZ hosts. A compromised host used as an AI proxy is a quiet, high-confidence intrusion indicator.
  6. Update IR playbooks. Add "AI-assisted intrusion" as a scenario: shortened dwell time assumptions, higher payload variety, and the possibility that exfiltrated data is being summarized/processed through an attacker-controlled LLM session (relevant for legal/regulatory breach assessment in financial jurisdictions).
  7. Follow vendor research. Monitor CrowdStrike's threat research portal and Anthropic's threat-intelligence reporting for IOC and account-level disruption updates as this attribution matures.

The Bottom Line

The significance of the CrowdStrike disclosure isn't that AI was used — it's that an agentic framework ran a coordinated intrusion against hardened financial targets with a single operator. Your adversary's marginal cost of sophistication just dropped to near zero. Defenders who respond by tightening egress, accelerating detection windows, and hunting for machine-speed behavior will absorb this shift. Defenders still operating on dwell-time assumptions from 2023 will not.

Related Resources

Security Arsenal Red Team Services AlertMonitor Platform Book a SOC Assessment pen-testing Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.