The Attacker Left the Session Logs Open: CrowdStrike’s ARTEX Operator Dossier

Two days after we covered the seven-bank ARTEX campaign, the case broke open twice: first from the attacker's own infrastructure, then from the tool's author. CrowdStrike Intelligence published on 7 October a reconstruction of the operation built not from victim telemetry but from the operator’s exposed open directories — Claude Code session histories, ARTEX configuration files and Claude memory files sitting on attacker-controlled servers. Then on 8 October, ARTEX's developer announced the project is going closed-source, Reuters reported on 9 October, with the GitHub page taken down.

The combination is the rarest thing in incident reporting: a full-stack view of an AI-executed intrusion campaign, from the model backends to the monetisation plan to the suspect's résumé — followed immediately by the tooling author's attempt to put the capability back in the box.

What CrowdStrike found in the open directories

CrowdStrike identified infrastructure tied to a campaign active from late September to early October 2026 against South Korean financial organisations, resulting in exfiltrated data. The attribution is carefully bounded: the activity has not been attributed to a named adversary, and the assessment — likely a Chinese speaker, financially motivated — is made with moderate confidence, based on the Chinese-developed ARTEX tooling and observed Chinese-language prompts.

  • The ARTEX host. IP 38.244.50[.]120 hosted an ARTEX instance and an open directory containing a Claude Code document at :18899/.claude/CLAUDE.md — a Chinese-language pentesting prompt specifying how the LLM should conduct testing. A Hong Kong–based IP address appearing in that document led to further open directories.
  • Two-server architecture. The Hong Kong IP serves as the primary attacker-controlled infrastructure; 38.244.50[.]120 hosts the ARTEX instance assessed as responsible for the Korean attacks. Targeted organisations overlap with those in industry reporting.
  • Three model backends. The ARTEX instance used DeepSeek v4.1-flash as the primary LLM, supplemented with GLM-5.3 (Zhipu AI) and Grok 4.6 for additional Claude Code sessions. CrowdStrike assesses the operator likely reached DeepSeek through the probable LLM API proxy/reseller xcai[.]pro.
  • Nine proxy IPs observed in the sessions: 101.53.80[.]20, 205.214.59[.]31, 124.155.252[.]63, 154.201.79[.]246, 23.248.249[.]90, 23.158.220[.]98, 103.248.148[.]84, 203.160.133[.]172, 209.209.85[.]38.
  • The monetisation trail. The operator asked Claude where threat actors typically sell Korean data-breach information and for help finding Korean Telegram data-sales groups. Sessions also show vulnerability research against a Telegram-based NFT gift marketplace and targeting of a possible Chinese payment platform.

The résumé prompt — evidence with its own warning label

In one session, the operator asked Claude to draft a security-researcher résumé packaging the ARTEX campaign's results, supplying personal details: the name YY, a phone number, the Telegram handle @YY520CN, age 26, South China University of Technology education, and a Maoming, Guangdong location. The same handle appears in the NFT-marketplace research sessions. CrowdStrike’s caveat is explicit and worth repeating verbatim in spirit: the details likely belong to the operator, but currently available information cannot definitively associate them with the threat actor.

Note the internal contradiction CrowdStrike preserves rather than smooths over: the résumé claims age 26 while the supplied birth date is 2007-09-22. Operator-supplied PII in an attacker's own prompt is evidence, not identity — it may be real, aspirational, or someone else's. Treat the handle as an infrastructure pivot, not a person.

A day later, the author pulls the tool

On Thursday 8 October, the developer behind ARTEX — GitHub handle Autumn-27 — posted that "given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided," per Reuters. The developer said ARTEX was built to help enterprises test security risk, opposed illegal use, and disclaimed responsibility for lawbreaking. Reuters' own checks confirmed the GitHub page taken down. At least nine banks have now disclosed or been reported as targets, and China's foreign ministry said Thursday it was "not familiar with the case."

Closed-sourcing stops future releases. It does not recall the copies already cloned during the two weeks the tool was both famous and public — the same distribution irreversibility we traced through a year of S1ngularity, Shai-Hulud and TeamPCP. The capability is out; only the update channel is closed.

Why the session-log angle matters for defenders

CrowdStrike’s core assessment is about tempo: AI tooling let a financially motivated actor run multiple intrusions in a short span, and adversaries will keep experimenting to sharpen operational pace. But the forensic method is itself the defensive lesson. Agentic operators generate the same artefact sprawl as enterprise agent deployments — session histories, memory files, config files, default ports (:18899 here) — and they expose it to the internet at the same rate. Every red-team convenience (a readable CLAUDE.md, an open directory, an unrotated proxy reseller) is a detection surface. Threat hunting for attacker infrastructure can use the same markers defenders use to inventory their own agents: default tool ports, framework path conventions, and session-file formats.

The LLM-supply detail deserves its own line in your threat model. The operator did not just call model APIs — they routed through a third-party proxy/reseller. Unknown LLM endpoints in agent configs, whether yours or the attacker's, are now a legitimate hunting indicator alongside unknown C2 domains.

What to do

  • Ingest the CrowdStrike IOCs as attributed, not confirmed-bad. The ARTEX host, the nine proxy IPs and the reseller domain are one vendor's campaign reconstruction with moderate-confidence attribution. Block or alert, but track them as a cluster that stands or falls together.
  • Hunt ARTEX markers with the closed-source caveat. The tool's console strings and default paths still work as detection artefacts — but expect forks and renames now that the canonical repo is gone. Hunt the behaviour (autonomous pentest-agent traffic patterns against auxiliary portals) alongside the strings.
  • Flag unknown LLM API endpoints at egress. Agent traffic to reseller/proxy domains outside your approved model-vendor list — the xcai.pro pattern — is worth an alert whether it comes from your developers or your adversary.
  • Apply the session-sprawl lesson inward. If an attacker's Claude Code histories can reconstruct their whole campaign, so can yours. Scope, encrypt and expire agent session logs and memory files; a red-team engagement's history directory is a credential and TTP archive.
  • Re-read the prior briefing's basics. The entry points were unauthenticated PII lookups, soft staff portals and unpatched web servers — the MFA-and-patching controls that held last time still hold.

Verification note: campaign timing, infrastructure detail, model backends, proxy IPs, résumé contents and the moderate-confidence assessment are CrowdStrike’s 7 October Counter Adversary Operations blog as fetched 9 October; the "cannot definitively associate" caveat is theirs. The closed-source statement, GitHub takedown, nine-bank scope and MFA-spokesperson comment are Reuters (via The Hindu, 9 October). We have not independently verified the IOCs or the operator details; the phone number from the résumé prompt is deliberately not reproduced here.

Sources: