AI-Powered Cyberattacks Target South Korean Financial Sector, Highlighting Evolving Threat Landscape
Cybersecurity researchers at CrowdStrike have uncovered a targeted campaign against South Korean financial institutions, leveraging an AI-driven penetration testing tool named ARTEX to facilitate data exfiltration. The operation, active from late September to early October 2026, marks a concerning evolution in cyber threats, where open-source AI tools are repurposed for malicious use.
The attack infrastructure relied on a Hong Kong-based IP address (38.244.50[.]120), which hosted the ARTEX instance and exposed session histories, configuration files, and memory logs from Claude Code, an AI collaboration platform. While the threat actor remains unattributed, evidence suggests a Chinese-speaking operator motivated by financial gain.
ARTEX, developed by Autumn-27, is an LLM-powered autonomous penetration testing system originally designed for legitimate security research. However, in this campaign, it was paired with multiple AI models, including DeepSeek v4.1-flash (accessed via the reseller xcai[.]pro), Z.ai’s GLM-5.3, and SpaceXAI’s Grok 4.6. The threat actor also used Claude to identify Telegram groups selling stolen Korean financial data, with session logs referencing the Telegram account @YY520CN and the alias "YY."
In response to the misuse, Autumn-27 discontinued ARTEX’s open-source availability, citing violations of its intended purpose authorized security testing for enterprises. The developer emphasized that the tool was never meant for malicious activities and will no longer receive updates or support.
AI-Driven Credential Stuffing Emerges in Parallel Attack
Separately, cybersecurity firm ZenoX revealed details of SCARLET LOOP, a Portuguese-speaking, financially motivated threat actor operating an AI-powered credential stuffing and account takeover platform. The system automates the entire attack chain, from target selection to login execution, using a combination of OpenAI’s GPT-5.6 (for dork generation), GPT-5.5 (for target classification), and DeepSeek models to bypass anti-automation defenses.
The platform employs an AI-driven Firefox browser that spoofs device fingerprints (canvas, WebGL, time zone, etc.) and outsources CAPTCHA solving. It operates in four phases:
- Target discovery – AI identifies high-value Brazilian loyalty, corporate incentives, and gift card platforms.
- Credential sourcing – Stolen credentials are obtained from infostealer logs and data leaks.
- Login execution – An anti-detection browser agent autonomously navigates login forms, adapts to security measures, and exploits weaknesses.
- Exfiltration – Successful credentials are sent to a private Telegram channel in the format ✅ {url} {user}:{password}.
Notably, the system features an "AUTO Mode" that removes AI from the loop after repeated successful logins on the same domain, optimizing token usage. Analysis of the exposed server revealed 12.3 million credentials tested, with 11,832 confirmed valid across 3,968 domains.
These incidents underscore a growing trend: threat actors are increasingly integrating AI into their operations to enhance speed, scalability, and evasion capabilities. The shift from open-source AI tools to closed-source models driven by misuse further complicates the cybersecurity landscape, as malicious actors adapt to new restrictions.
Source: https://thehackernews.com/2026/10/artex-ai-pentesting-tool-used-in-data.html
Autumn-27 TPRM report: https://www.rankiteo.com/company/autumn-cashmere
"id": "aut1791477837",
"linkid": "autumn-cashmere",
"type": "Vulnerability",
"date": "10/2026",
"severity": "25",
"impact": "1",
"explanation": "Attack without any consequences"
{'affected_entities': [{'industry': 'Finance',
'location': 'South Korea',
'type': 'Financial institutions'},
{'industry': 'Retail/E-commerce',
'location': 'Brazil',
'type': 'Loyalty/gift card platforms'}],
'attack_vector': ['AI-powered tools (ARTEX, Claude, DeepSeek, GLM-5.3, Grok '
'4.6)',
'Automated browser agents with anti-detection capabilities'],
'data_breach': {'data_exfiltration': 'Yes (via Telegram channels)',
'number_of_records_exposed': '11,832 (confirmed valid '
'credentials)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Financial data',
'Credentials',
'Personally identifiable '
'information (PII)']},
'date_detected': '2026-09-01',
'description': 'Cybersecurity researchers at CrowdStrike uncovered a targeted '
'campaign against South Korean financial institutions, '
'leveraging an AI-driven penetration testing tool named ARTEX '
'to facilitate data exfiltration. Separately, a '
'Portuguese-speaking threat actor used an AI-powered '
'credential stuffing platform (SCARLET LOOP) to automate '
'account takeovers.',
'impact': {'data_compromised': ['Stolen Korean financial data',
'12.3 million credentials tested (11,832 '
'confirmed valid)'],
'identity_theft_risk': ['High (PII exposure)'],
'payment_information_risk': ['High (financial data targeted)'],
'systems_affected': ['South Korean financial institutions',
'Brazilian loyalty/gift card platforms']},
'initial_access_broker': {'data_sold_on_dark_web': 'Yes (via Telegram)',
'entry_point': ['AI-powered penetration testing '
'tool (ARTEX)',
'Automated credential stuffing '
'platform (SCARLET LOOP)'],
'high_value_targets': ['South Korean financial '
'institutions',
'Brazilian loyalty/gift card '
'platforms']},
'investigation_status': 'Ongoing',
'lessons_learned': 'Threat actors are increasingly integrating AI into cyber '
'operations to enhance speed, scalability, and evasion '
'capabilities. Misuse of open-source AI tools complicates '
'the cybersecurity landscape.',
'motivation': ['Financial gain'],
'post_incident_analysis': {'corrective_actions': ['Discontinuation of ARTEX '
'open-source availability',
'Enhanced monitoring of AI '
'tool misuse'],
'root_causes': ['Misuse of legitimate AI tools',
'Automated anti-detection '
'techniques',
'Exposed AI session '
'logs/configurations']},
'references': [{'source': 'CrowdStrike'},
{'source': 'ZenoX'},
{'source': 'Autumn-27 (ARTEX developer)'}],
'response': {'containment_measures': ['ARTEX open-source availability '
'discontinued'],
'third_party_assistance': ['CrowdStrike', 'ZenoX']},
'threat_actor': ['Unattributed (Chinese-speaking, financially motivated)',
'SCARLET LOOP (Portuguese-speaking, financially motivated)'],
'title': 'AI-Powered Cyberattacks Target South Korean Financial Sector',
'type': ['AI-driven penetration testing misuse',
'Credential stuffing',
'Account takeover'],
'vulnerability_exploited': ['Repurposed legitimate AI tools for malicious use',
'Bypassing anti-automation defenses',
'Exposed session histories and configuration '
'files']}