{"artifact":{"id":"art-crowdstrike-artex-incident-analysis-20261007","dedupe_key":"813325b547da7f4d14b03e5e49cb8740f0857b071bc9704368653dbdaf6da977","canonical_url":"https://crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korea-finance","evidence_locator":"","artifact_type":"incident_analysis","title":"CrowdStrike ARTEX-assisted intrusion analysis","summary":"CrowdStrike analyzed attacker-controlled infrastructure, ARTEX configuration and Claude Code session histories associated with targeting of South Korean financial institutions and reported data exfiltration.","creator_entities":["CrowdStrike"],"released_at":"2026-10-07T00:00:00.000Z","content_hash":null,"metadata":[],"created_at":"2026-10-08T15:30:24.567Z","updated_at":"2026-10-08T15:30:24.567Z"},"sources":[{"id":"src-crowdstrike-artex-south-korea-20261007","dedupe_key":"c724a02087bbf99bbdfe7db99dc4c805396428ce2d473fc57c879a8c93ec3ef2","name":"Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance","publisher":"CrowdStrike","url":"https://crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance","evidence_locator":"","source_type":"primary_security_analysis","primary_or_secondary":"primary","retrieved_at":"2026-10-08T06:21:53.000Z","published_at":"2026-10-07T00:00:00.000Z","author":"CrowdStrike","metadata":[],"created_at":"2026-10-08T15:30:24.564Z","updated_at":"2026-10-08T15:30:24.564Z"}]}