Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Tool ARTEX Exploited in South Korean Data Breaches

AI Tool ARTEX Exploited in South Korean Data Breaches

Posted on October 8, 2026 By CWS

AI Technology in Cyber Attacks

A recent investigation by cybersecurity experts has uncovered a series of attacks on South Korean financial institutions, utilizing an AI-powered pen testing tool named ARTEX. These incidents, revealed by CrowdStrike Intelligence, spanned from late September to early October 2026, resulting in significant data theft.

The attackers employed ARTEX, an open-source penetration testing tool developed in China, alongside advanced language models to facilitate the breaches. CrowdStrike discovered the campaign through open directories on a Hong Kong server, revealing session histories and configuration files related to ARTEX.

Unidentified Threat Actors

The identity of those responsible for the attacks remains uncertain, though evidence suggests the involvement of Chinese-speaking individuals motivated by financial gain. ARTEX, developed by Autumn-27, is a sophisticated tool that uses multiple AI models to perform penetration testing autonomously.

The infrastructure behind the attacks included a Hong Kong-based IP address acting as a central hub, with an IP of “38.244.50[.]120” hosting the ARTEX instance. This setup utilized several AI models like DeepSeek v4.1-flash and Z.ai’s GLM-5.3 to enhance its capabilities.

Response to ARTEX Misuse

The misuse of ARTEX has prompted its developers to make the tool closed source, aiming to prevent further exploitation. Autumn-27 expressed that the tool’s purpose was purely educational, designed to aid organizations in assessing security risks.

In response to its abuse, the developers have halted updates and ceased maintenance support, distancing themselves from the malicious activities conducted using ARTEX.

SCARLET LOOP’s AI-Powered Exploits

In a related development, ZenoX has revealed details about a separate operation called SCARLET LOOP, which uses AI for credential stuffing and account takeovers. This campaign, led by a Portuguese-speaking group, automates the process of hijacking accounts using stolen credentials.

SCARLET LOOP employs AI to identify high-value targets, execute logins, and extract valid credentials, using models like OpenAI’s GPT-5.6 for search query generation. The operation has tested millions of credentials, highlighting the growing trend of AI in enhancing the efficiency of cybercriminals.

These findings underscore the increasing reliance on AI technologies by threat actors to amplify the scale and sophistication of their attacks, posing significant challenges to cybersecurity defenses worldwide.

The Hacker News Tags:account takeover, AI security, ARTEX tool, Autumn-27, Chinese threat actors, Claude Code, credential stuffing, CrowdStrike, Cybersecurity, data breach, DeepSeek, financial sector, SCARLET LOOP, South Korea, ZenoX

Post navigation

Previous Post: Critical LMCache Vulnerability Allows Unauthorized Code Execution
Next Post: Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Related Posts

Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign Abandoned Sogou Zhuyin Update Server Hijacked, Weaponized in Taiwan Espionage Campaign The Hacker News
Anthropic Introduces Claude Code Security for AI Vulnerability Scanning Anthropic Introduces Claude Code Security for AI Vulnerability Scanning The Hacker News
Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets Tomiris Shifts to Public-Service Implants for Stealthier C2 in Attacks on Government Targets The Hacker News
Cybersecurity Threats Evolve: Key Developments Cybersecurity Threats Evolve: Key Developments The Hacker News
30,000 Facebook Accounts Hacked in Phishing Scam 30,000 Facebook Accounts Hacked in Phishing Scam The Hacker News
Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot Malicious Go Module Poses as SSH Brute-Force Tool, Steals Credentials via Telegram Bot The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VirusTotal API Keys Allegedly Sold on Dark Web
  • Fortinet Devices Targeted by FortiBleed Attackers
  • Japan Faces Surge in Data Breaches Due to API and Software Vulnerabilities
  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark