ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
A suspected Chinese operator used the ARTEX AI pentest tool to steal data from South Korean financial firms.
CrowdStrike Intelligence reported a late September to early October 2026 campaign against South Korean financial organizations that used ARTEX, an open-source agentic penetration-testing tool from Chinese developer Autumn-27, together with LLMs, and resulted in data exfiltration. The activity, tied to a Hong Kong IP and a suspected Chinese-speaking financially motivated operator, used DeepSeek v4.1-flash as the main model with GLM-5.3 and Grok 4.6. Autumn-27 then closed-sourced ARTEX. Separately, ZenoX described SCARLET LOOP, a Portuguese-speaking actor’s agentic credential-stuffing platform that tested 12,277,358 credentials and validated 11,832 across 3,968 domains.