Skip to main content

Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

0
Medium
Published: 10/09/2026 (10/09/2026, 08:13:35 UTC)
Source: AlienVault OTX General

Description

An unidentified, likely Chinese-speaking, financially motivated threat actor targeted South Korean financial institutions between late September and early October 2026, successfully exfiltrating data. The attacker used ARTEX, an open-source Chinese agentic penetration testing tool, combined with large language models such as DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 to enhance operational tempo and conduct multiple intrusions rapidly. Analysis revealed exposed ARTEX configuration files, Claude Code session histories, and a two-server infrastructure involving Hong Kong. The adversary also researched Korean data breach marketplaces and Telegram channels for monetizing stolen data. The campaign demonstrates sophisticated use of AI-driven tooling to conduct targeted intrusions against financial institutions.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/09/2026, 08:52:25 UTC

Technical Analysis

This threat involves a financially motivated, likely Chinese-speaking threat actor conducting targeted attacks against South Korean financial institutions using ARTEX, a Chinese-developed open-source agentic penetration testing tool, augmented by large language models (DeepSeek v4.1-flash, GLM-5.3, Grok 4.6). The attacker leveraged AI to increase operational tempo, enabling multiple intrusions within a short timeframe. Exposed directories contained ARTEX configuration files and Claude Code session histories, revealing a two-server architecture with infrastructure based in Hong Kong. The adversary also investigated Korean data breach marketplaces and Telegram channels for selling stolen information. Indicators include multiple IP addresses and a domain associated with the campaign. There is no known CVE or exploit code associated with this threat, and no patch or remediation is applicable as this is an active threat actor campaign rather than a software vulnerability.

Potential Impact

The threat actor successfully exfiltrated data from targeted South Korean financial institutions, indicating a breach of confidentiality and potential financial and reputational damage. The use of AI-driven tools allowed rapid and multiple intrusions, increasing the scale and speed of compromise. The actor's research into data marketplaces suggests intent to monetize stolen information, posing ongoing risk to affected entities and their customers.

Defensive Guidance

No specific patch or fix applies as this is an active threat actor campaign rather than a software vulnerability. Organizations should focus on detection and response capabilities tailored to the tactics, techniques, and procedures (TTPs) observed, including monitoring for ARTEX-related activity and AI-powered attack patterns. Review and harden access controls, network segmentation, and incident response plans. Refer to vendor advisories and threat intelligence updates for evolving indicators and recommended defensive measures.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/"]
Pulse Id
6ac8a22f8d0ad1ea5f056ddc

Indicators of Compromise

Ip

ValueDescriptionCopy
ip38.244.50.120
—
ip101.53.80.20
—
ip205.214.59.31
—
ip124.155.252.63
—
ip154.201.79.246
—
ip23.248.249.90
—
ip23.158.220.98
—
ip103.248.148.84
—
ip203.160.133.172
—
ip209.209.85.38
—

Domain

ValueDescriptionCopy
domainxcai.pro
—

Threat ID: 6ac8a6ed2cdf04f6563e890f

Added to database: 10/09/2026, 08:33:49 UTC

Last enriched: 10/09/2026, 08:52:25 UTC

Last updated: 10/09/2026, 18:48:09 UTC

Views: 25

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses