CrowdStrike says a financially motivated attacker used ARTEX, an open-source agentic penetration testing tool, to steal data from South Korean financial organizations.
The Hacker News reports that CrowdStrike Intelligence has detailed a campaign, active from late September to early October 2026, in which an unidentified attacker used ARTEX, a recently released open-source agentic penetration testing tool developed in China, to break into South Korean financial organizations and exfiltrate data. The tool coordinates multiple LLM-driven agents to automate reconnaissance, vulnerability discovery and exploitation, and the instance seen in this campaign ran primarily on a DeepSeek model. Researchers believe the operator is a Chinese speaker motivated by financial gain, and ARTEX's developer has since taken the project closed source, saying it was meant only for learning and research.
Why it matters: freely available agentic offensive tools lower the skill and time needed to find and exploit weaknesses in internet-facing services. Security teams should assume faster, automated probing of exposed apps such as partner and employee portals, and prioritise attack-surface reduction, patching and detection of machine-speed reconnaissance.