✳ the wire · analysis

CrowdStrike: an open-source AI pentest agent running DeepSeek V4.1 Flash hit South Korean banks

DeepSeek V4.1 Flashconfirmedby ArtificialWatch

Get launch alerts like this, free →

CrowdStrike: an open-source AI pentest agent running DeepSeek V4.1 Flash hit South Korean banks
Source imagery · verified against a primary source

CrowdStrike says an open-source AI penetration-testing agent called ARTEX, running on DeepSeek V4.1 Flash, was behind the data breaches at South Korean financial organizations from late September to early October. Its report, published October 7, rests on the attacker's own files, which it found in open directories on attacker-controlled servers: Claude Code session histories, ARTEX configuration files and Claude memory files.

WHAT CROWDSTRIKE FOUND

- ARTEX is a recently released, Chinese-developed tool that drives an LLM through a pentest. The attacker's instance used DeepSeek V4.1 Flash as its main model, likely bought through an API reseller. - The attacker supplemented it with Zhipu's GLM-5.3 and xAI's Grok 4.6 in additional Claude Code sessions. - A Chinese-language pentesting prompt in a CLAUDE.md file told the model how to run the attacks. - The session histories also show the attacker asking Claude where Korean breach data is usually sold, and for help finding Telegram groups that trade it. - One session asked Claude to write a security-researcher résumé listing the results of the campaign. CrowdStrike says the personal details in that prompt likely belong to the attacker but can't yet confirm it.

WHO IT WAS

CrowdStrike hasn't tied the activity to a named group. It assesses with moderate confidence that the attacker is a Chinese speaker and financially motivated, based on the Chinese-developed tool and the Chinese-language prompts. Its conclusion: AI tooling let one financially motivated actor carry out several intrusions in a short span.

WHAT WE DO NOT KNOW

How many organizations were hit: CrowdStrike says the number is unconfirmed. Nor does the report say how much of the work the models did on their own and how much the attacker did by hand.

Source: CrowdStrike Intelligence (report, read directly) ↗ · DeepSeek V4.1 Flash tracker · the bench index

sweeping every 60 seconds

Know the minute it drops — not the minute we write it up.

Claude Opus 5 went live at 16:51 UTC. The alert was in subscribers' inboxes at 16:52.

  • Free forever
  • No card
  • Unsubscribe in one click

← back to the wire