hacker-news · Crawled Oct 9, 2026

ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

8 IoCs
Read original article ↗

AI Summary

A targeted campaign against South Korean financial firms, including Shinhan Bank and Yegaram Savings Bank, leveraged the open-source AI-powered penetration testing tool ARTEX, developed by Autumn-27, to conduct data theft operations. The attacks, active from late September to early October 2026, involved a suspected Chinese-speaking threat actor using a Hong Kong-based IP address hosting the ARTEX instance and interacting with LLMs such as DeepSeek, GLM, and Grok. The actor also used Claude to research methods for selling stolen Korean data on Telegram and referenced the Telegram account @YY520CN. CrowdStrike linked the activity to financial motivation, though no group has been definitively attributed. In response, the ARTEX developer discontinued the project and moved it to closed source due to misuse.

AI-extracted · verify before operational use

Indicators of Compromise 8 extracted

Type Value Detail
IP 38[.]244[.]50[.]120 Details →
Domain xcai[.]pro Details →
GitHub User Autumn-27 Details →
GitHub Repo Autumn-27/ARTEX Details →
Domain 127[.]0[.]0[.]1 Details →
Filename ARTEX configuration files Details →
Filename Claude memory files Details →
Filename Claude Code session histories Details →