HomeSecurityARTEX: The AI ​​pentesting tool for data theft attacks

ARTEX: The AI ​​pentesting tool for data theft attacks

Cybersecurity researchers have uncovered a targeted attack campaign against financial institutions in South Korea, allegedly using ARTEX, an pen testing . The activity was recorded from late September to early October 2026 and, according to the findings, resulted in a data leak.

Article Image: ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

The case highlights the risks that arise when tools developed for legitimate security audits are exploited by cybercriminals. It also shows how incorporating large language models (LLMs) into attack processes can facilitate the automation of tasks that traditionally required significant technical expertise.

According to cybersecurity firm CrowdStrike Intelligence, the attackers combined ARTEX's capabilities with different artificial intelligence models, attempting to organize and execute actions against their targets.

How the attack campaign was revealed

CrowdStrike detected the activity after discovering exposed file directories on a server with an IP address in Hong Kong . The files included Claude Code session histories , Claude memory data, and ARTEX configuration files .

See also: CrowdStrike links South Korean bank breaches to AI tools and suspect from China

Exposing such information can give investigators a rare insight into how a cyberattack was orchestrated. Rather than relying solely on technical clues, such as malicious files or suspicious connections, analysts can examine the commands given to AI systems, the tasks performed, and the decisions recorded during the activity.

In this case, analysis of the available data revealed a two-server architecture, with the Hong Kong infrastructure being a key point of operational activity. In particular, the IP address 38.244.50[.]120 hosted the ARTEX installation suspected of being linked to the attacks against South Korean organizations.

The campaign has not yet been definitively attributed to any known cybercriminal group. However, the investigation points to a possible Chinese-speaking operator who may be financially motivated. This assessment does not constitute a definitive identification of the perpetrator.

ARTEX AI - SecNews.gr

ARTEX and multiple artificial intelligence models

ARTEX is a penetration testing system developed by Autumn-27 and is based on a multi-AI agent architecture. Rather than being limited to executing a single command, such a system can coordinate different tasks through individual AI agents, which work together to achieve a larger goal.

In the context of legitimate testing, this approach can help security experts automate audits, identify vulnerabilities, and assess the resilience of information systems. However, when used without authorization, the same automation can accelerate target identification and execution of offensive actions.

According to CrowdStrike, the suspected ARTEX installation used DeepSeek v4.1-flash as its base model, while also leveraging Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6. Researchers believe the operator may have accessed DeepSeek through the API reseller xcai[.]pro, although this has not been definitively confirmed.

Using more than one model can provide greater flexibility to an automated system, allowing it to leverage different capabilities depending on the task. At the same time, it complicates investigation, as analysts need to consider not only the tool's infrastructure, but also its interactions with external AI services.

Searches for the sale of stolen data

Another element that stood out in the investigation concerns the suspected operator's efforts to identify channels for distributing data stolen from South Korean organizations.

CrowdStrike reported that in recorded sessions, the user allegedly asked Claude where perpetrators typically sell data from breaches related to South Korea. He also asked for help identifying Telegram groups that sell such information.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

One of Claude Code’s sessions featured a reference to the Telegram account “@YY520CN” and the name “YY.” The same username had also been spotted in other sessions investigating vulnerabilities in an NFT gift exchange platform via Telegram.

However, these clues alone are not enough to prove that the account belongs to the perpetrator of the ARTEX campaign. CrowdStrike notes that while the data may be related to the operator, there is insufficient documentation to make a definitive connection.

See also: Google retires Dark Web Monitoring Tool

ARTEX creator abandons open source model

The revelation of the potential malicious use of ARTEX led its creator to announce significant changes to the project. Autumn-27 stated that the attackers' activity is not linked to him and emphasized that using the tool for attacks goes against the original purpose of its development.

As he explained, ARTEX was created for educational and research purposes, with the aim of helping businesses and organizations assess the security of their approved systems and strengthen their defenses against real threats.

However, due to the abuse that was discovered, the creator announced that the project will no longer receive updates and will become closed source. No new releases, technical support, or maintenance are planned.

The decision highlights a broader dilemma for the cybersecurity community. Open source tools allow for transparency, independent evaluation, and collaboration among researchers. But at the same time, free access to their code can make them easier to adapt for malicious operations.

Security check of autonomous agents

What the case means for business security

This campaign highlights that artificial intelligence in itself is neither a threat nor a guarantee of security. The risk depends largely on how it is used, the automation capabilities, and the level of access granted to the operator.

See also: 'CrashStealer' malware mimics Apple tool and targets Macs

For financial institutions, protection requires a combination of timely installation of updates, restriction of access rights, continuous monitoring of networks and effective event logging. It is also important to protect servers from incorrect configurations that can expose session files, credentials or internal information.

The ARTEX case ultimately shows that the evolution of AI tools is changing the balance in the cybersecurity space. Organizations are called upon to leverage automation to strengthen their defenses, without underestimating the possibility that the same technologies could be used to escalate attacks and accelerate the exploitation of sensitive data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS