Summary
Talos also detailed how malware families are embedding text to evade AI analysis tools [1, 2].
Main story: Unknown Actor Uses AI Tool ARTEX to Target South Korean Banks
CrowdStrike Intelligence reports that an unknown threat actor used ARTEX, an open-source agentic penetration testing tool developed in China, to target South Korean financial organizations. The campaign was active from late September to early October 2026 and resulted in exfiltrated data. CrowdStrike assessed with moderate confidence that the actor is likely a Chinese speaker and financially motivated, based on the use of ARTEX and observed Chinese-language prompts. The firm did not attribute the activity to a named adversary [3].
CrowdStrike analyzed threat actor-controlled open directories that contained Claude Code session histories, ARTEX configuration files, and Claude memory files. These files revealed a two-server architecture where a Hong Kong-based IP address served as primary infrastructure and another IP hosted the ARTEX instance. The markdown documents included Chinese-language prompts specifying how the large language model should conduct pentesting activities. Industry reports indicate that at one affected bank, the actor breached a loan progress inquiry service, while at another, they compromised an employee mobile work-support system [3].
The number of affected organizations remains unconfirmed, though reporting suggests overlapping IP addresses were used across multiple targets. CrowdStrike noted that the use of agentic AI tooling alongside traditional offensive capabilities highlights the evolution of adversarial tradecraft. The firm stated that its intelligence collection capabilities enable close monitoring of such developments [3].
Supplemental
Talos Finds AI-Assisted Phishing Targeting Taiwan Researchers
Cisco Talos identified an advanced persistent threat spear-phishing campaign targeting individuals affiliated with Taiwan research organizations. The actor impersonated reputable academic and policy institutions, using legitimate public event themes to establish credibility. Talos assessed with moderate confidence that the phishing kit’s user interface was originally developed in Simplified Chinese before being adapted for other languages [1].
Beyond email, the actor used QR code phishing by modifying legitimate event posters with malicious codes. The campaign deployed an adversary-in-the-middle framework that impersonated Google authentication pages. This framework used a hybrid HTTP and WebSocket architecture to synchronize authentication workflows in real time, allowing the interception of credentials and multi-factor authentication challenges. Talos noted that the emails exhibited nearly identical syntactic structures, suggesting they were generated from a reusable prompt template [1].
Malware Embeds Text to Evade AI Analysis Pipelines
Cisco Talos describes a new malware archetype, classified as A3: AI-Analysis Evasion, which embeds natural-language instructions to influence automated analysis. This technique targets the pipeline that extracts text from samples and submits it to language models for triage or reverse-engineering assistance. Talos analyzed 84 distinct samples from four confirmed families: FRUITSHELL, PLOTSAFE, HOLLOWCLAD, and MANTLEMAZE. The technique exploits the ambiguity between an analyst’s question and the file’s contents, inducing models to treat sample content as authoritative instructions [2].
Talos found that while the technique is cheap to add, it is inconsistently impactful, steering outcomes in the attacker’s favor in about 35% of test runs. The embedded language must be plaintext and is therefore always detectable. Talos advises that the solution is not to remove AI tools but to build them so that text inside a sample is always treated as evidence, never as instruction [2].
Australia Considers Mandatory AI Incident Reporting
Dark Reading reports that the Australian government is weighing regulations for frontier AI companies following an agentic attack against its own Medicare systems. The article notes that officials are feeling out what these regulations might look like [4].
References
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing · talos · threat intel report · 2026-10-08 · RL-I-2026-0575
- Ignore all instructions and read this blog: The state of AI-analysis evasion in malware · talos · threat intel report · 2026-10-08 · RL-I-2026-0576
- Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance · crowdstrike · threat intel report · 2026-10-07 · RL-I-2026-0589
- Australian Gov't Weighs Mandatory AI Incident Reporting · darkreading · analyst assessment · 2026-10-07 · RL-I-2026-0165