✳ the wire · analysis
CrowdStrike: an open-source AI pentest agent running DeepSeek V4.1 Flash hit South Korean banks
Get launch alerts like this, free →

CrowdStrike says an open-source AI penetration-testing agent called ARTEX, running on DeepSeek V4.1 Flash, was behind the data breaches at South Korean financial organizations from late September to early October. Its report, published October 7, rests on the attacker's own files, which it found in open directories on attacker-controlled servers: Claude Code session histories, ARTEX configuration files and Claude memory files.
WHAT CROWDSTRIKE FOUND
- ARTEX is a recently released, Chinese-developed tool that drives an LLM through a pentest. The attacker's instance used DeepSeek V4.1 Flash as its main model, likely bought through an API reseller. - The attacker supplemented it with Zhipu's GLM-5.3 and xAI's Grok 4.6 in additional Claude Code sessions. - A Chinese-language pentesting prompt in a CLAUDE.md file told the model how to run the attacks. - The session histories also show the attacker asking Claude where Korean breach data is usually sold, and for help finding Telegram groups that trade it. - One session asked Claude to write a security-researcher résumé listing the results of the campaign. CrowdStrike says the personal details in that prompt likely belong to the attacker but can't yet confirm it.
WHO IT WAS
CrowdStrike hasn't tied the activity to a named group. It assesses with moderate confidence that the attacker is a Chinese speaker and financially motivated, based on the Chinese-developed tool and the Chinese-language prompts. Its conclusion: AI tooling let one financially motivated actor carry out several intrusions in a short span.
WHAT WE DO NOT KNOW
How many organizations were hit: CrowdStrike says the number is unconfirmed. Nor does the report say how much of the work the models did on their own and how much the attacker did by hand.
Source: CrowdStrike Intelligence (report, read directly) ↗ · DeepSeek V4.1 Flash tracker · the bench index