INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ArTEX AI-Driven Attack Targets South Korean Finance Institutions
| 2026-10-09 08:13 AI-ENABLED ATTACK DATA BREACH
Executive Summary
AI-generated
An unidentified threat actor, likely Chinese-speaking and financially motivated, conducted targeted attacks against South Korean financial institutions between late September and early October 2026, successfully exfiltrating data. The adversary utilized ARTEX, a Chinese-developed open-source agentic penetration testing tool, combined with large language models including DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6. Analysis of exposed directories revealed Claude Code session histories, ARTEX configuration files, and operational details showing a two-server architecture involving Hong Kong-based infrastructure. The threat actor demonstrated sophisticated tradecraft by leveraging AI tooling to enhance operational tempo, enabling multiple intrusions within a compressed timeframe. Evidence suggests the attacker also researched Korean data breach marketplaces and Telegram channels for selling stolen information, targeting South Korean finance institutions in early October 2026, with indicators of compromise pointing to China-based infrastructure and involving ARTEX, Grok, and other malware families.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
xc•••••.pro
203.160.•••.•••
23.248.•••.•••
103.248.•••.•••
23.158.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Intelligence Sources
AlienVault OTX
2026-10-09