Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

    Date: 10/08/2026

    Severity: High

    Summary

    Researchers details a financially motivated threat actor targeting South Korean financial organizations using ARTEX, an open-source agentic penetration-testing tool, alongside LLMs. The campaign leveraged AI-assisted intrusion operations, Claude Code, proxy infrastructure, and attacker-controlled servers, resulting in data exfiltration from targeted organizations. The activity included vulnerability research against a Telegram-based NFT marketplace, with the Telegram platform,  highlighting the emerging use of agentic AI and LLMs to automate and accelerate reconnaissance, vulnerability research, and offensive cyber operations. 

    Indicators of Compromise (IOC) List 

    IP Address

    101.53.80.20

    103.248.148.84

    124.155.252.63

    154.201.79.246

    203.160.133.172

    205.214.59.31

    209.209.85.38

    23.158.220.98

    23.248.249.90

    38.244.50.120

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    dstipaddress IN ("203.160.133.172","205.214.59.31","23.158.220.98","103.248.148.84","154.201.79.246","38.244.50.120","23.248.249.90","124.155.252.63","101.53.80.20","209.209.85.38") or srcipaddress IN ("203.160.133.172","205.214.59.31","23.158.220.98","103.248.148.84","154.201.79.246","38.244.50.120","23.248.249.90","124.155.252.63","101.53.80.20","209.209.85.38")

    Reference:    

    Unknown Threat Actor Uses AI-Driven ARTEX                                             


    Tags

    MalwareThreat ActorSouth KoreaLLMsAIExfiltrationFinancial ServicesTelegram

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags