INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ArTEX AI Pentesting Tool Used in Data Theft Attacks

| 2026-10-08 14:12 HIGH MEDIUM AI-ENABLED ATTACK · AUTONOMOUS DATA BREACH
Executive Summary
AI-generated
A targeted campaign using the recently released open-source agentic penetration testing tool ARTEX, developed in China, carried out attacks on South Korean financial organizations from late September to early October 2026. The attack is believed to be driven by a suspected Chinese-speaking operator with financial gain as their motive and has resulted in data exfiltration. The campaign was discovered after identifying open directories hosted at a Hong Kong-based IP address, exposing ARTEX configuration files among other sensitive information. The attackers used a two-server architecture, with the Hong Kong-based IP address hosting an instance of ARTEX suspected to be behind the attacks; this ARTEX instance utilized DeepSeek v4.1-flash as its main LLM backend and Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 for supplementation.
Technical Mitigations AI-generated
• Block or hunt for the IP address "38.244.50[.]120" and its associated ARTEX instance using DeepSeek v4.1-flash, Z.ai's GLM-5.3, and SpaceXAI's Grok 4.6. • Use a LLM API reseller like "@<a href="/auth/login?next=/detail/SuwxH6EBAhlSTKR_3ZAi" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN &bull; LOGIN REQUIRED]</span></a>." to detect potential misuse of the LLM backend. • Monitor for suspicious activity related to vulnerability research on Telegram-based NFT gift marketplaces using the username "YY520CN" or "YY". • Implement measures to prevent unauthorized access to ARTEX configuration files and session histories.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

xc•••••.pro
38.244.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
HK KR BR CN
Incident Timeline
‎2026/10/08
Threat actors used the ARTEX AI pentesting tool to carry out data theft attacks on South Korean financial firms from late September to early October 2026.
organisation LLM
organisation SpaceXAI
organisation OpenAI
‎October 2026
A financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP used ARTEX AI pentesting tool to conduct credential stuffing and account takeover attacks on South Korean financial firms.
organisation ARTEX
organisation CrowdStrike
organisation IP
organisation Google Gemini
organisation Google
organisation WebGL
organisation SCARLET LOOP Uses AI for Account Takeover
organisation Telegram
organisation NFT
organisation Target
organisation The Hacker News
data_breach 12,277,358 credentials
data_breach 11,832 credentials
infrastructure 3,968 domains
Tactical Metrics
Metrics
data_breach
12,277,358
Credentials
Metrics
data_breach
11,832
Credentials
Metrics
infrastructure
3,968
Domains
Intelligence Sources