ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms

Summary

Cybersecurity researchers have identified a targeted campaign against South Korean financial firms that utilized an AI-powered penetration testing tool called ARTEX. The campaign, active in late September and early October 2026, successfully exfiltrated data from the targeted organizations.

IFF Assessment

FOE

The use of AI-powered tools like ARTEX by threat actors for data theft represents an advancement in attack capabilities, posing a significant threat to defenders.

Defender Context

This incident highlights the growing sophistication of cyberattacks, with threat actors leveraging AI tools for penetration testing and data exfiltration against critical financial infrastructure. Defenders need to stay vigilant against novel attack vectors and the misuse of legitimate security tools by malicious actors, particularly in the financial sector.

Read Full Story →