AI Technology in Cyber Attacks
A recent investigation by cybersecurity experts has uncovered a series of attacks on South Korean financial institutions, utilizing an AI-powered pen testing tool named ARTEX. These incidents, revealed by CrowdStrike Intelligence, spanned from late September to early October 2026, resulting in significant data theft.
The attackers employed ARTEX, an open-source penetration testing tool developed in China, alongside advanced language models to facilitate the breaches. CrowdStrike discovered the campaign through open directories on a Hong Kong server, revealing session histories and configuration files related to ARTEX.
Unidentified Threat Actors
The identity of those responsible for the attacks remains uncertain, though evidence suggests the involvement of Chinese-speaking individuals motivated by financial gain. ARTEX, developed by Autumn-27, is a sophisticated tool that uses multiple AI models to perform penetration testing autonomously.
The infrastructure behind the attacks included a Hong Kong-based IP address acting as a central hub, with an IP of “38.244.50[.]120” hosting the ARTEX instance. This setup utilized several AI models like DeepSeek v4.1-flash and Z.ai’s GLM-5.3 to enhance its capabilities.
Response to ARTEX Misuse
The misuse of ARTEX has prompted its developers to make the tool closed source, aiming to prevent further exploitation. Autumn-27 expressed that the tool’s purpose was purely educational, designed to aid organizations in assessing security risks.
In response to its abuse, the developers have halted updates and ceased maintenance support, distancing themselves from the malicious activities conducted using ARTEX.
SCARLET LOOP’s AI-Powered Exploits
In a related development, ZenoX has revealed details about a separate operation called SCARLET LOOP, which uses AI for credential stuffing and account takeovers. This campaign, led by a Portuguese-speaking group, automates the process of hijacking accounts using stolen credentials.
SCARLET LOOP employs AI to identify high-value targets, execute logins, and extract valid credentials, using models like OpenAI’s GPT-5.6 for search query generation. The operation has tested millions of credentials, highlighting the growing trend of AI in enhancing the efficiency of cybercriminals.
These findings underscore the increasing reliance on AI technologies by threat actors to amplify the scale and sophistication of their attacks, posing significant challenges to cybersecurity defenses worldwide.
