AI Tool Linked to Financial-Sector Hacks Found on Hundreds of Servers; Hacker's Identity Under Investigation (Roundup)
- Input
- 2026-10-08 15:21:36
- Updated
- 2026-10-08 15:21:36

[Financial News] Hundreds of servers running the AI-based penetration-testing tool 'ARTEX,' which appears to have been used in recent hacks targeting South Korea's financial sector, have been observed worldwide. It has also emerged that a hacker who attacked South Korean financial firms used generative AI to search for outlets selling leaked Korean data. As AI is being used not only for hacking but also to find channels for trading stolen information, concerns about secondary harm are growing. Police have obtained analysis from an overseas cybersecurity firm that raised the possibility the attacker is a 26-year-old resident of China's Guangdong Province, and are tracing the hacker's identity.■ Limits of detecting attacks by blocking malicious IPs aloneAccording to a threat intelligence note released on the 8th by security and data intelligence company S2W, hundreds of servers running the same tool as 'ARTEX'—whose use in recent financial-sector hacking has been indicated—were observed worldwide. 'ARTEX' is an open-source, AI-based penetration-testing tool originally developed to check companies' security vulnerabilities. When a user sets a target, AI can gather information, search for vulnerabilities, and design attack paths, among other tasks.
After analyzing attack information shared by financial authorities, S2W found records showing that a relay program connecting the ARTEX management interface to an AI model was also running at one of the IP addresses used in the attack. The server had been active since early September, and is believed to have stopped operating after related news reports. S2W said an investigation by the authorities would be needed to determine whether AI actually carried out any part of the process of stealing personal information.
The attackers are believed to have changed their access addresses by alternating between rented servers overseas and commercial proxy services. Most of the IP addresses used in the attacks had almost no prior reports of malicious activity in existing global threat intelligence databases. This meant the attacks were difficult to detect using existing methods that rely solely on blocking malicious IPs.
The targets were supplementary services, such as loan inquiries, rather than banks' core IT networks. The attacker is believed to have repeatedly changed customer numbers to access other customers' information. The attacker exploited a weakness in the authorization process, which checks whether users have permission to access information, even after they have authenticated themselves through means such as logging in.■ Asked AI even about outlets selling leaked data... Tracking a possible 26-year-old hacker in ChinaEvidence was also found that the hacker targeting South Korean financial firms used generative AI to search for outlets selling leaked Korean data. In a report released on the 7th (local time), global cybersecurity company CrowdStrike said it had found records showing that the attacker asked Anthropic's generative AI, Claude, where leaked Korean data is generally sold, and requested that it find Telegram groups related to the sale of Korean data.
CrowdStrike found conversation records from Claude Code, Claude's coding tool, and ARTEX configuration files in a public directory on a server managed by the attacker. The analysis indicated that the attacker used a server based in Hong Kong as the main attack infrastructure and connected the Chinese AI model DeepSeek to 'ARTEX.' Several other large language models (LLMs), including GLM and Grok, were also used for additional tasks.
Clues that could help identify the attacker were also found. The attacker asked Claude Code to write a security researcher résumé featuring penetration-testing work using ARTEX, and entered their name initials, Telegram account, educational background, and place of residence. The records included information that the person was 26 years old and lived in Maoming, Guangdong Province, China.
Police are stepping up efforts to trace the attacker using this information as a lead. They have obtained and are analyzing information about the attacker's identity presented by CrowdStrike. Police believe that many of the 28 IP addresses related to the case were used for 'laundering' to evade tracking, and are continuing their investigation, including through international cooperation.
[email protected] Choi Hye-rim, Kim Ye-ji Reporter