Date: 10/08/2026
Severity: High
Summary
Researchers details a financially motivated threat actor targeting South Korean financial organizations using ARTEX, an open-source agentic penetration-testing tool, alongside LLMs. The campaign leveraged AI-assisted intrusion operations, Claude Code, proxy infrastructure, and attacker-controlled servers, resulting in data exfiltration from targeted organizations. The activity included vulnerability research against a Telegram-based NFT marketplace, with the Telegram platform, highlighting the emerging use of agentic AI and LLMs to automate and accelerate reconnaissance, vulnerability research, and offensive cyber operations.
Indicators of Compromise (IOC) List
IP Address | 101.53.80.20 103.248.148.84 124.155.252.63 154.201.79.246 203.160.133.172 205.214.59.31 209.209.85.38 23.158.220.98 23.248.249.90 38.244.50.120 |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | dstipaddress IN ("203.160.133.172","205.214.59.31","23.158.220.98","103.248.148.84","154.201.79.246","38.244.50.120","23.248.249.90","124.155.252.63","101.53.80.20","209.209.85.38") or srcipaddress IN ("203.160.133.172","205.214.59.31","23.158.220.98","103.248.148.84","154.201.79.246","38.244.50.120","23.248.249.90","124.155.252.63","101.53.80.20","209.209.85.38") |
Reference:
Unknown Threat Actor Uses AI-Driven ARTEX