INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ArTEX AI-Driven Attack Targets South Korean Finance Institutions

| 2026-10-09 08:13 CRITICAL MEDIUM AI-ENABLED ATTACK DATA BREACH
Executive Summary
AI-generated
An unidentified threat actor, likely Chinese-speaking and financially motivated, conducted targeted attacks against South Korean financial institutions between late September and early October 2026, successfully exfiltrating data. The adversary utilized ARTEX, a Chinese-developed open-source agentic penetration testing tool, combined with large language models including DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Analysis of exposed directories revealed Claude Code session histories, ARTEX configuration files, and operational details showing a two-server architecture involving Hong Kong-based infrastructure. The threat actor demonstrated sophisticated tradecraft by leveraging AI tooling to enhance operational tempo, enabling multiple intrusions within a compressed timeframe. Evidence suggests the attacker also researched Korean data breach marketplaces and Telegram channels for selling stolen information, targeting South Korean finance institutions in early October 2026, with indicators of compromise pointing to China-based infrastructure and involving ARTEX, Grok, and other malware families.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

xc•••••.pro
203.160.•••.•••
23.248.•••.•••
103.248.•••.•••
23.158.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
NORTH_AMERICA NORTH_AMERICA financefinance
Incident Timeline
‎early October 2026
An unidentified threat actor, likely Chinese-speaking and financially motivated, used AI-driven ARTEX to target South Korean financial institutions between late September and early October 2026.
target_region Korea, Republic of
‎October 2026
An unknown threat actor used the Chinese-developed open-source agentic penetration testing tool ARTEX, combined with large language models, to target South Korean finance.
organisation Telegram
organisation ARTEX
‎2026/10/09
An unknown threat actor utilized an AI-driven ARTEX malware family to target South Korean finance institutions.
organisation Target South Korean Finance
Intelligence Sources