Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Blackpink’s Lisa Manobal: How the K-pop star faced a race scandal

    October 11, 2026

    Security Sunday: Europas Krieg der Zukunft — mit Nico Lange – POLITICO

    October 11, 2026

    Apple discloses deal to hire team and license tech from personalized podcast startup Huxe

    October 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Blackpink’s Lisa Manobal: How the K-pop star faced a race scandal
    • Security Sunday: Europas Krieg der Zukunft — mit Nico Lange – POLITICO
    • Apple discloses deal to hire team and license tech from personalized podcast startup Huxe
    • Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
    • Here’s a Way to Predict When AI Chatbots Will Turn Bad
    • Did two of the lemurs stolen in Bangladesh end up in India? Officials are investigating
    • ‘Time for Ukraine to get new president,’ says Trump after Zelensky condemns diesel deal
    • AI agent makers are promising privacy — will they deliver?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Sunday, October 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 11, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.

    The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration from various South Korea-based financial firms, including Shinhan Bank and Yegaram Savings Bank.

    “In this activity, the threat actor leveraged ARTEX, a recently released open-source agentic penetration testing (pentesting) tool developed in China, alongside large language models (LLMs),” the cybersecurity company said.

    CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files.

    The campaign has not been attributed to any known threat actor or group. But evidence points to a suspected Chinese-speaking operator driven by financial gain.

    ARTEX is a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27. Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture –

    • The Hong Kong-based IP address functions as the backbone of the campaign
    • The IP address “38.244.50[.]120” hosts the ARTEX instance suspected to be behind the attacks on Korean attacks

    The ARTEX instance has been found to use DeepSeek v4.1-flash as the main LLM backend, while using Z.ai’s GLM-5.3 and SpaceXAI’s Grok 4.6 to supplement the model. It’s suspected that the threat actor accessed DeepSeek likely via the LLM API reseller “xcai[.]pro.”

    Cybersecurity

    “In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups,” CrowdStrike said.

    In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named “@YY520CN” and the name “YY.” Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.

    “While the personal details included in the prompt likely belong to the threat actor who conducted the ARTEX-related activity, currently available information cannot definitively associate these details with the threat actor,” CrowdStrike concluded.

    The breaches have triggered a warning from South Korea’s Financial Services Commission and Financial Supervisory Service, urging financial consumers to exercise vigilance and be on the lookout for potential phishing attacks and loan scams stemming from leaked data.

    In an October 8, 2026, message posted on their Telegram channel, @YY520CN said, “I didn’t do anything. South Korea just wants to blame all the untraceable things on me and other innocent ordinary people, so that they can solve all the problems without taking their own responsibility.”

    ARTEX Goes Closed Source

    The misuse of ARTEX has prompted Autumn-27 to take it closed source, with the developer emphasizing in a statement that the malicious attacks had nothing to do with them. They also said the malicious use of the tool violates the original purpose of the tool.

    “ARTEX was originally designed for the purpose of learning and research,” Autumn-27 said. “It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities.”

    “In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future.”

    SCARLET LOOP Uses AI for Account Takeover

    The development comes as ZenoX disclosed details of an agentic credential stuffing and account takeover platform orchestrated by a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP.

    The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale. The entire process unfolds in four steps –

    • Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms.
    • Obtaining credentials specific to each target
    • Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation
    • Exfiltrating successful credentials in the format “✅ {url} {user}:{password}” to a private Telegram channel

    While OpenAI’s GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash.

    Also configured are Anthropic’s Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google’s gemma-4-26B-A4B set up as a local model served at “127.0.0[.]1:1237.”

    Cybersecurity

    “An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result,” the Brazilian cybersecurity company said in a report shared with The Hacker News.

    “In the discovery and login phases the agent acts without step-by-step supervision and autonomously maps unfamiliar login surfaces, discovers security weaknesses, and generates purpose-built automation to exploit them.”

    Interestingly, the platform also supports an “AUTO Mode” during the login execution phase that removes the AI model from the loop after a set number of successful logins on the same target domain. The idea is to save on tokens and use them sparingly only when an unfamiliar login form is encountered.

    “Model reasoning is expensive and slow,” ZenoX said. “It is indispensable on the first visit to an unknown form and unnecessary on the thousandth. The platform was built to pay for intelligence exactly once per target, and then stop paying.”

    Analysis of the internet-exposed server hosting the platform has revealed that 12,277,358 credentials were tested, out of which 11,832 credentials have been classified as valid across 3,968 domains.

    The findings once again illustrate how threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities.

    ARTEX attacks data Financial firms Korean Pentesting South theft tool
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

    Invasive species have more severe environmental impacts in Global South, study finds

    Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys

    Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Blackpink’s Lisa Manobal: How the K-pop star faced a race scandal

    October 11, 2026

    Security Sunday: Europas Krieg der Zukunft — mit Nico Lange – POLITICO

    October 11, 2026

    Apple discloses deal to hire team and license tech from personalized podcast startup Huxe

    October 11, 2026

    Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia

    October 11, 2026
    Latest Posts

    Trump media group racks up losses and pushes into nuclear fusion

    August 10, 2026

    Live: Russian missiles strike Kyiv, triggering fires in city centre

    August 10, 2026

    Dragon roars with record power in Faroe Islands: Minesto hits new tidal energy output milestone

    August 11, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Blackpink’s Lisa Manobal: How the K-pop star faced a race scandal

    October 11, 2026

    Security Sunday: Europas Krieg der Zukunft — mit Nico Lange – POLITICO

    October 11, 2026

    Apple discloses deal to hire team and license tech from personalized podcast startup Huxe

    October 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.