ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.

Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.
The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration.
CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files.
The campaign has not been attributed to any known threat actor or group.
Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture - The ARTEX instance has been found to use DeepSeek v4.1-flash as the main LLM backend, while using Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 to supplement the model.
"In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source.
ARTEX is a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27 .
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named and the name Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
It's suspected that the threat actor accessed DeepSeek likely via the LLM API reseller CrowdStrike said.
The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale.
There will be no release of any version or maintenance support in the future." The development comes as ZenoX disclosed details of an agentic credential stuffing and account takeover platform orchestrated by a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP.
The entire process unfolds in four steps - While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating.
The idea is to save on tokens and use them sparingly only when an unfamiliar login form is encountered.
Chrome responded by blocking the unauthorized certificates for Google properties through CRLSets, the mechanism Chrome uses to quickly block certificates in emergencies.
What happened
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.
The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration.
CrowdStrike said it discovered the campaign after it identified a set of open directories hosted at a Hong Kong-based IP address, exposing Claude Code session histories, Claude memory files, and ARTEX configuration files.
What changed
The campaign has not been attributed to any known threat actor or group.
Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture - The ARTEX instance has been found to use DeepSeek v4.1-flash as the main LLM backend, while using Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 to supplement the model.
"In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source.
Who is affected
ARTEX is a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27 .
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named and the name Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
Why it matters
It's suspected that the threat actor accessed DeepSeek likely via the LLM API reseller CrowdStrike said.
The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale.
Technical details
There will be no release of any version or maintenance support in the future." The development comes as ZenoX disclosed details of an agentic credential stuffing and account takeover platform orchestrated by a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP.
The entire process unfolds in four steps - While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating.
The idea is to save on tokens and use them sparingly only when an unfamiliar login form is encountered.
Response
Chrome responded by blocking the unauthorized certificates for Google properties through CRLSets, the mechanism Chrome uses to quickly block certificates in emergencies.
Google proactively blocked those certificates in Chrome and said it contacted affected organizations where possible.
What security teams should do
Google said browser-side blocking should not be relied on because its analysis may not have identified every affected domain and Chrome's interventions do not reliably protect non-Chrome users.
Google recommended that domain owners continuously monitor CT logs across their entire domain portfolios, including parked and regional ccTLD properties.
What remains unknown
"It is indispensable on the first visit to an unknown form and unnecessary on the thousandth.
The data revealed a large-scale credential-harvesting operation, although it was unclear at the time what method was used to obtain the configuration data.
It did not say how widespread the campaign was.
Attribution
The Hacker News: Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks.
Infosecurity Magazine: The incidents affected the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) namespaces, according to a post published by Google's Chrome Secure Web and Networking Team on October 6.
Infosecurity Magazine: In the email to customers on October 8, shared with Infosecurity, ASOS also confirmed that payment information was not compromised and that the incident has not affected operations.
Infosecurity Magazine: The cybersecurity firm discovered that the attacker used ARTEX, a recently released open-source agentic pentesting tool developed in China alongside Anthropic’s Claude AI model during the campaign, which ran from late September to early October 2026.
What to watch next
Watch for additional victim details, indicators of compromise and follow-on exploitation reports.
Watch for revised vendor guidance, fixed versions and mitigation updates.