Threats Tagged 'artex'
View all threats tagged with 'artex'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'artex'
Click on any threat for detailed analysis and mitigation recommendations
An unidentified, likely Chinese-speaking, financially motivated threat actor targeted South Korean financial institutions between late September and early October 2026, successfully exfiltrating data. The attacker used ARTEX, an open-source Chinese agentic penetration testing tool, combined with large language models such as DeepSeek v4.1-flash, GLM-5.3, and Grok 4.6 to enhance operational tempo and conduct multiple intrusions rapidly. Analysis revealed exposed ARTEX configuration files, Claude Code session histories, and a two-server infrastructure involving Hong Kong. The adversary also researched Korean data breach marketplaces and Telegram channels for monetizing stolen data. The campaign demonstrates sophisticated use of AI-driven tooling to conduct targeted intrusions against financial institutions. Join the discussion | AlienVault OTX General | 10/09/2026, 08:13:35 UTC Added: 10/09/2026, 08:33:49 UTC |
Showing 1 to 1 of 1 result