Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AI Tool ARTEX Exploited in South Korean Data Breaches

AI Tool ARTEX Exploited in South Korean Data Breaches

Posted on October 8, 2026 By CWS

AI Technology in Cyber Attacks

A recent investigation by cybersecurity experts has uncovered a series of attacks on South Korean financial institutions, utilizing an AI-powered pen testing tool named ARTEX. These incidents, revealed by CrowdStrike Intelligence, spanned from late September to early October 2026, resulting in significant data theft.

The attackers employed ARTEX, an open-source penetration testing tool developed in China, alongside advanced language models to facilitate the breaches. CrowdStrike discovered the campaign through open directories on a Hong Kong server, revealing session histories and configuration files related to ARTEX.

Unidentified Threat Actors

The identity of those responsible for the attacks remains uncertain, though evidence suggests the involvement of Chinese-speaking individuals motivated by financial gain. ARTEX, developed by Autumn-27, is a sophisticated tool that uses multiple AI models to perform penetration testing autonomously.

The infrastructure behind the attacks included a Hong Kong-based IP address acting as a central hub, with an IP of “38.244.50[.]120” hosting the ARTEX instance. This setup utilized several AI models like DeepSeek v4.1-flash and Z.ai’s GLM-5.3 to enhance its capabilities.

Response to ARTEX Misuse

The misuse of ARTEX has prompted its developers to make the tool closed source, aiming to prevent further exploitation. Autumn-27 expressed that the tool’s purpose was purely educational, designed to aid organizations in assessing security risks.

In response to its abuse, the developers have halted updates and ceased maintenance support, distancing themselves from the malicious activities conducted using ARTEX.

SCARLET LOOP’s AI-Powered Exploits

In a related development, ZenoX has revealed details about a separate operation called SCARLET LOOP, which uses AI for credential stuffing and account takeovers. This campaign, led by a Portuguese-speaking group, automates the process of hijacking accounts using stolen credentials.

SCARLET LOOP employs AI to identify high-value targets, execute logins, and extract valid credentials, using models like OpenAI’s GPT-5.6 for search query generation. The operation has tested millions of credentials, highlighting the growing trend of AI in enhancing the efficiency of cybercriminals.

These findings underscore the increasing reliance on AI technologies by threat actors to amplify the scale and sophistication of their attacks, posing significant challenges to cybersecurity defenses worldwide.

The Hacker News Tags:account takeover, AI security, ARTEX tool, Autumn-27, Chinese threat actors, Claude Code, credential stuffing, CrowdStrike, Cybersecurity, data breach, DeepSeek, financial sector, SCARLET LOOP, South Korea, ZenoX

Post navigation

Previous Post: Critical LMCache Vulnerability Allows Unauthorized Code Execution
Next Post: Hackers Exploit Atlassian Vulnerability Soon After Disclosure

Related Posts

Evolving Beyond vCISO: The Rise of Security Growth Platforms Evolving Beyond vCISO: The Rise of Security Growth Platforms The Hacker News
UNC6671 Cyber Threat Intensifies with Vishing Attacks UNC6671 Cyber Threat Intensifies with Vishing Attacks The Hacker News
Langflow Vulnerability Exploited Within Hours of Revelation Langflow Vulnerability Exploited Within Hours of Revelation The Hacker News
n8n Webhooks Exploited for Malware Delivery via Phishing n8n Webhooks Exploited for Malware Delivery via Phishing The Hacker News
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat The Hacker News
Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 Tunneling The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zammad Flaw Allows Remote Code Execution via Session Leak
  • Hackers Exploit Atlassian Vulnerability Soon After Disclosure
  • AI Tool ARTEX Exploited in South Korean Data Breaches
  • Critical LMCache Vulnerability Allows Unauthorized Code Execution
  • Cisco Releases Patches for Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark