CrowdStrike said on Wednesday that one attacker ran the open penetration-testing tool ARTEX against five South Korean lenders. Investigators read the attacker's own Claude Code logs, which held a résumé CrowdStrike thinks is his. ARTEX's author then removed the GitHub page, and the project is now closed to the public.