[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f83cTX72riDqbanVRBwONdsN-OWz82JSzvJ26desCQ3U":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":31,"category":32,"article_tags":36},"8afc87e1-e3dc-4543-9d65-58207a7226f9","ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms","artex-ai-pentesting-tool-used-in-data-theft-attacks-on-south-korean-financial-fi-50bd0e","Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. \"In this activity, the threat actor leveraged","Cybersecurity researchers disclosed a targeted campaign against South Korean financial organizations using ARTEX, an open-source AI pentesting tool developed in China, from late September to early October 2026. The threat actor leveraged ARTEX alongside LLMs (DeepSeek, GLM-5.3, Grok 4.6) to conduct data exfiltration, with evidence pointing to a Chinese-speaking, financially motivated operator. Following the misuse, ARTEX developer Autumn-27 converted the tool to closed-source and ceased updates.","ARTEX AI pentesting tool used in data theft attacks on South Korean financial firms","ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms Ravie LakshmananOct 08, 2026Agentic AI \u002F Web Security Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. \"In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs),\" the cybersecurity company said. CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files. The campaign has not been attributed to any known threat actor or group. But evidence points to a suspected Chinese-speaking operator driven by financial gain. ARTEX is a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27. Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture - The Hong Kong-based IP address functions as the backbone of the campaign The IP address \"38.244.50[.]120\" hosts the ARTEX instance suspected to be behind the attacks on Korean attacks The ARTEX instance has been found to use DeepSeek v4.1-flash as the main LLM backend, while using Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 to supplement the model. It's suspected that the threat actor accessed DeepSeek via the likely LLM API reseller \"xcai[.]pro.\" \"In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups,\" CrowdStrike said. In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named \"@YY520CN\" and the name \"YY.\" Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username. \"While the personal details included in the prompt likely belong to the threat actor who conducted the ARTEX-related activity, currently available information cannot definitively associate these details with the threat actor,\" CrowdStrike concluded. ARTEX Goes Closed Source The misuse of ARTEX has prompted Autumn-27 to take it closed source, with the developer emphasizing in a statement that the malicious attacks had nothing to do with them. They also said the malicious use of the tool violates the original purpose of the tool. \"ARTEX was originally designed for the purpose of learning and research,\" Autumn-27 said. \"It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities.\" \"In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future.\" SCARLET LOOP Uses AI for Account Takeover The development comes as ZenoX disclosed details of an agentic credential stuffing and account takeover platform orchestrated by a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP. The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale. The entire process unfolds in four steps - Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms. Obtaining credentials specific to each target Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation Exfiltrating successful credentials in the format \"✅ {url} {user}:{password}\" to a private Telegram channel While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash. Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at \"127.0.0[.]1:1237.\" \"An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result,\" the Brazilian cybersecurity company said in a report shared with The Hacker News. \"In the discovery and login phases the agent acts without step-by-step supervision and autonomously maps unfamiliar login surfaces, discovers security weaknesses, and generates purpose-built automation to exploit them.\" Interestingly, the platform also supports an \"AUTO Mode\" during the login execution phase that removes the AI model from the loop after a set number of successful logins on the same target domain. The idea is to save on tokens and use them sparingly only when an unfamiliar login form is encountered. \"Model reasoning is expensive and slow,\" ZenoX said. \"It is indispensable on the first visit to an unknown form and unnecessary on the thousandth. The platform was built to pay for intelligence exactly once per target, and then stop paying.\" Analysis of the internet-exposed server hosting the platform has revealed that 12,277,358 credentials were tested, out of which 11,832 credentials have been classified as valid across 3,968 domains. The findings once again illustrate how threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  artificial intelligence, Cybercrime, data breach, Financial Security, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell","https:\u002F\u002Fthehackernews.com\u002F2026\u002F10\u002Fartex-ai-pentesting-tool-used-in-data.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEjrg8bHUppR3zYriUhWwJig9yJq8F69XCeJrtY040zk39DNhblhBRkcTcQSqRo6K3PwnMVoygOCmbWf2X7ySQDxpfDlgmXFBDGhoiicnG3_5E84RhV6muyzgGacKye5eiB5dLcvsNfny5yS-4TlrypAdPcU1PVfT-jMxWvdfg9algqsvxycUV1Jy1xUjGiT\u002Fs1600\u002Fai-hacker.jpg","2026-10-08T14:12:34+00:00","2026-10-08T16:00:11.298445+00:00",9,[18,21,23,26,28],{"name":19,"type":20},"CrowdStrike","vendor",{"name":22,"type":20},"Autumn-27",{"name":24,"type":25},"DeepSeek","technology",{"name":27,"type":25},"Claude",{"name":29,"type":30},"SCARLET LOOP","campaign","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":31,"icon":33,"name":34,"slug":35},null,"AI Security","ai-security",[37,42,47],{"category":38},{"id":39,"icon":33,"name":40,"slug":41},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":43},{"id":44,"icon":33,"name":45,"slug":46},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":48},{"id":49,"icon":33,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53,57,61],{"type":54,"value":55,"context":56},"ip","38.244.50.120","IP address hosting ARTEX instance suspected to be behind attacks on Korean financial firms",{"type":58,"value":59,"context":60},"domain","xcai.pro","LLM API reseller likely used by threat actor to access DeepSeek",{"type":46,"value":62,"context":63},"ARTEX","Open-source agentic AI pentesting tool misused for data exfiltration attacks"]