Ethical Hacking News
A recent campaign by a suspected Chinese-speaking operator used ARTEX, an AI pen testing tool, to carry out targeted attacks on South Korean financial firms. The attack resulted in data exfiltration and has prompted the developer of the tool to take it closed source. This development comes as threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. The misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks.
The misuse of ARTEX has been attributed to a suspected Chinese-speaking operator driven by financial gain. The campaign was active from late September to early October 2026 and resulted in data exfiltration. The threat actor leveraged ARTEX, a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27, alongside large language models (LLMs). Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture.
In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future. This development comes as threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. The misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks.
The misuse of ARTEX has been attributed to a suspected Chinese-speaking operator driven by financial gain. The campaign was active from late September to early October 2026 and resulted in data exfiltration. The threat actor leveraged ARTEX, a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27, alongside large language models (LLMs). Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture.
The entire process unfolds in four steps: Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms. Obtaining credentials specific to each target, Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation. Exfiltrating successful credentials in the format "✅ {url} {user}:{password}" to a private Telegram channel.
While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash. Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at "127.0.0[.]1:1237."
"An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result," the Brazilian cybersecurity company said in a report shared with The Hacker News.
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named "@YY520CN" and the name "YY." Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
ARTEX, a recently released open-source agentic penetration testing tool, has been found to be misused by a suspected Chinese-speaking operator for financial gain. A targeted campaign aimed at South Korean financial organizations used ARTEX to carry out data exfiltration. Autumn-27 has taken the decision to make ARTEX closed source in response to its misuse. A suspected Portuguese-speaking operator has been using the SCARLET LOOP platform to automate credential stuffing and account takeover attacks. SCARLET LOOP uses AI agents to bypass defenses and exfiltrate credentials to a private Telegram channel. Security teams lack visibility, controls, and governance to keep track of AI tool misuse in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data.
In a disturbing trend that highlights the rapidly evolving threat landscape, cybersecurity researchers have recently disclosed details of a targeted campaign aimed at South Korean financial organizations that utilized an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. This development comes as ARTEX, a recently released open-source agentic penetration testing tool developed in China, has been found to be misused by a suspected Chinese-speaking operator driven by financial gain.
According to CrowdStrike Intelligence, the activity in question was active from late September to early October 2026 and resulted in data exfiltration. In this activity, the threat actor leveraged ARTEX, a large language model (LLM) multi-agent-driven autonomous penetration system developed by Autumn-27, alongside large language models (LLMs). Analysis of the Claude Code sessions from the Hong Kong IP address has revealed a two-server architecture - The Hong Kong-based IP address functions as the backbone of the campaign, while the IP address "38.244.50[.]120" hosts the ARTEX instance suspected to be behind the attacks on Korean financial firms.
The ARTEX instance has been found to use DeepSeek v4.1-flash as the main LLM backend, while using Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 to supplement the model. It is suspected that the threat actor accessed DeepSeek via the likely LLM API reseller "xcai[.]pro." Furthermore, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups.
While the personal details included in the prompt likely belong to the threat actor who conducted the ARTEX-related activity, currently available information cannot definitively associate these details with the threat actor. This has led to a significant concern for cybersecurity researchers, who are now under increased scrutiny to keep track of the misuse of AI tools in various attacks.
In response to the misuse of ARTEX, Autumn-27 has taken the decision to make the tool closed source. The developer emphasized in a statement that the malicious attacks had nothing to do with them and that the malicious use of the tool violates the original purpose of the tool. "ARTEX was originally designed for the purpose of learning and research," Autumn-27 said. "It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities." "In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future."
This development comes as ZenoX disclosed details of an agentic credential stuffing and account takeover platform orchestrated by a financially motivated, Portuguese-speaking actor dubbed SCARLET LOOP. The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale. The entire process unfolds in four steps: Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms.
Obtaining credentials specific to each target, Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation. Exfiltrating successful credentials in the format "✅ {url} {user}:{password}" to a private Telegram channel. While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash.
Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at "127.0.0[.]1:1237." "An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result," the Brazilian cybersecurity company said in a report shared with The Hacker News.
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named "@YY520CN" and the name "YY." Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
The misuse of ARTEX has prompted Autumn-27 to take it closed source, with the developer emphasizing in a statement that the malicious attacks had nothing to do with them. They also said the malicious use of the tool violates the original purpose of the tool. "ARTEX was originally designed for the purpose of learning and research," Autumn-27 said. "It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities."
In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future. This decision comes as threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities.
The misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data, while security teams still lack the visibility, controls, and governance to keep that access in check.
The discovery of the SCARLET LOOP platform has once again illustrated how threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale.
The entire process unfolds in four steps: Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms. Obtaining credentials specific to each target, Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation. Exfiltrating successful credentials in the format "✅ {url} {user}:{password}" to a private Telegram channel.
While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash. Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at "127.0.0[.]1:1237."
"An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result," the Brazilian cybersecurity company said in a report shared with The Hacker News.
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named "@YY520CN" and the name "YY." Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
The misuse of ARTEX has prompted Autumn-27 to take it closed source, with the developer emphasizing in a statement that the malicious attacks had nothing to do with them. They also said the malicious use of the tool violates the original purpose of the tool. "ARTEX was originally designed for the purpose of learning and research," Autumn-27 said. "It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities."
In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future.
In conclusion, the misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data, while security teams still lack the visibility, controls, and governance to keep that access in check.
The discovery of the SCARLET LOOP platform has once again illustrated how threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale.
The entire process unfolds in four steps: Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms. Obtaining credentials specific to each target, Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation. Exfiltrating successful credentials in the format "✅ {url} {user}:{password}" to a private Telegram channel.
While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash. Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at "127.0.0[.]1:1237."
"An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result," the Brazilian cybersecurity company said in a report shared with The Hacker News.
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named "@YY520CN" and the name "YY." Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
The misuse of ARTEX has prompted Autumn-27 to take it closed source, with the developer emphasizing in a statement that the malicious attacks had nothing to do with them. They also said the malicious use of the tool violates the original purpose of the tool. "ARTEX was originally designed for the purpose of learning and research," Autumn-27 said. "It aims to help enterprises and organizations conduct security risk tests within the scope of authorized assets and improve security protection capabilities."
In view of the reality of tool abuse, the ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future.
In the wake of the SCARLET LOOP platform being disclosed, cybersecurity researchers are now under increased scrutiny to keep track of the misuse of AI tools in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data, while security teams still lack the visibility, controls, and governance to keep that access in check.
The misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data, while security teams still lack the visibility, controls, and governance to keep that access in check.
In conclusion, the misuse of ARTEX has highlighted the growing need for better security controls and governance to keep track of the access and use of AI tools in various attacks. AI agents are already operating inside enterprises with growing access to sensitive systems and data, while security teams still lack the visibility, controls, and governance to keep that access in check.
The discovery of the SCARLET LOOP platform has once again illustrated how threat actors are increasingly adopting AI in their attacks to enhance their operational tempo and capabilities. The operation automates the entire process, right from victim selection to executing the login using stolen credentials obtained from infostealer logs and data leaks to hijack accounts at scale.
The entire process unfolds in four steps: Target discovery and qualification, which involves finding high-value targets using an AI classifier. Primary targets include Brazilian loyalty, corporate incentives, and gift cards platforms. Obtaining credentials specific to each target, Login execution, which employs an AI agent with an anti-detection browser to bypass defenses that detect automation. Exfiltrating successful credentials in the format "✅ {url} {user}:{password}" to a private Telegram channel.
While OpenAI's GPT-5.6 is used for dork generation (aka search queries) to find authentication pages of companies in a specific sector, GPT-5.5 is used for target classification and rating. The browser agent utilizes DeepSeek-V4-Pro and DeepSeek-V4-Flash. Also configured are Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash, and GLM-5.1 models, with Google's gemma-4-26B-A4B set up as a local model served at "127.0.0[.]1:1237."
"An LLM agent with 46 automation tools drives an instrumented Firefox that spoofs canvas, WebGL, time zone, language, geolocation and viewport, with outsourced captcha solving. The agent finds the login page, fills in the form and classifies the result," the Brazilian cybersecurity company said in a report shared with The Hacker News.
In one Claude Code session, the threat actor is said to have fed a prompt that referenced a Telegram account named "@YY520CN" and the name "YY." Other sessions related to vulnerability research on a Telegram-based NFT gift marketplace have also used the same Telegram username.
Related Information:
https://www.ethicalhackingnews.com/articles/ARTEX-AI-Pentesting-Tool-Misused-in-South-Korean-Financial-Data-Theft-Attacks-A-Growing-Concern-for-Cybersecurity-Researchers-ehn.shtml
https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html
Published: Thu Oct 8 11:58:18 2026 by llama3.2 3B Q4_K_M