ARTEX AI Pentesting Tool Targets South Korean Finance
Score: 8/10

ARTEX AI Pentesting Tool Targets South Korean Finance

Financially motivated actors are leveraging ARTEX, an open-source agentic AI pentesting tool, to automate breaches and data exfiltration from South Korean financial institutions.

Executive Summary

Beginning in late September 2026, a series of cyberattacks targeted major South Korean financial institutions, including KB Kookmin, Shinhan, and Hana Bank. The campaign involved the misuse of ARTEX, an autonomous 'agentic' penetration testing tool developed by a Chinese entity (Autumn-27). By leveraging large language models (LLMs) such as DeepSeek v4.1-flash, Claude, and Grok, the attackers automated vulnerability discovery and credential stuffing, resulting in the exfiltration of tens of thousands of personal data records.

Technically, the threat actor utilized a two-server architecture, with primary command-and-control operations routed through Hong Kong and automated attack instances hosted on separate infrastructure. While one specific Brazilian actor group, SCARLET LOOP, was identified using similar agentic methodologies for scale-based credential stuffing, the primary South Korean activity remains attributed to a suspected Chinese-speaking, financially motivated operator identified by the handle 'YY520CN'.

This activity marks a critical evolution in adversary tradecraft where autonomous AI agents reduce the cost and technical barrier for high-tempo, multi-target intrusions. The impact on the South Korean financial sector was immediate, leading to emergency government inspections and the subsequent closure of the ARTEX open-source project by its developer due to widespread abuse.

Key Details

Threat Name

ARTEX Financial Campaign

Affects

—

Adversary

SCARLET LOOP

Malware/Tools

ARTEX

Report Score

8out of 10
Quality Score
Good
IOC Quality8
TTP Details9
Detection Guidance4
Enterprise Relevance9
Clarity & Structure9
Technical Depth7

Sources