ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
AI Summary
A targeted campaign against South Korean financial firms, including Shinhan Bank and Yegaram Savings Bank, leveraged the open-source AI-powered penetration testing tool ARTEX, developed by Autumn-27, to conduct data theft operations. The attacks, active from late September to early October 2026, involved a suspected Chinese-speaking threat actor using a Hong Kong-based IP address hosting the ARTEX instance and interacting with LLMs such as DeepSeek, GLM, and Grok. The actor also used Claude to research methods for selling stolen Korean data on Telegram and referenced the Telegram account @YY520CN. CrowdStrike linked the activity to financial motivation, though no group has been definitively attributed. In response, the ARTEX developer discontinued the project and moved it to closed source due to misuse.
AI-extracted · verify before operational use
Indicators of Compromise 8 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 38[.]244[.]50[.]120 | Details → |
| Domain | xcai[.]pro | Details → |
| GitHub User | Autumn-27 | Details → |
| GitHub Repo | Autumn-27/ARTEX | Details → |
| Domain | 127[.]0[.]0[.]1 | Details → |
| Filename | ARTEX configuration files | Details → |
| Filename | Claude memory files | Details → |
| Filename | Claude Code session histories | Details → |