---
title: AI Hacking Tool ARTEX Found in Four Korean Servers, Cybersecurity Firm Tracks Global Infrastructure
url: https://www.elseif.net/ai-hacking-tool-artex-found-in-four-korean-servers-cybersecurity-firm-tracks-global-infrastructure
published: 2026-10-06T17:07:01+00:00
language: en
section: Harnesses
source: https://zdnet.co.kr/view/?no=20261004170058
organizations: ARTEX, Oasis Security, CyberStrikeAI, AdaptixC2, GoPhish, Shinhan Bank
publisher: elseif
---

# AI Hacking Tool ARTEX Found in Four Korean Servers, Cybersecurity Firm Tracks Global Infrastructure

Recent cyberattacks targeting major financial institutions in Korea have raised concerns, with evidence suggesting the use of an AI-based autonomous penetration testing tool called ARTEX. The tool's name was found in the HTML title of a web server allegedly involved in an attack on Shinhan Bank, indicating that ARTEX may have been operational or related environments were set up on that server. However, official investigations have not yet confirmed ARTEX's direct involvement in the attack. ARTEX is an open-source AI system that uses large language models to automate security validation processes. It allows security personnel to specify targets and scopes, enabling agents to explore assets, analyze vulnerabilities, and call necessary tools. The system is composed of a Go-based backend and a web frontend, offering features such as LLM settings, asset management, tool calls, and vulnerability scanning. By default, it provides web services through TCP port 8787. While ARTEX is designed for authorized penetration testing and security validation, its open-source nature allows anyone to deploy it, potentially enabling attackers to automate reconnaissance, vulnerability scanning, and attack preparation. Oasis Security, a cyber threat intelligence firm, has been tracking ARTEX's global infrastructure using its own CTI platform, AGATHA.

Between September 23 and October 3, the company identified 500 instances of ARTEX-related infrastructure, with 359 unique IP addresses and 392 different service exposures. Notably, 93% of these IPs were observed using ARTEX's default web service port, TCP 8787. The geographical distribution of ARTEX-related infrastructure shows a significant concentration in the United States, China, and Hong Kong, accounting for 91.4% of the total. However, these locations do not necessarily indicate the attacker's actual nationality or whereabouts, as attackers can use cloud services and overseas hosting to operate servers in different countries. Network provider analysis revealed that a substantial portion of ARTEX-related infrastructure is concentrated in specific networks, with PEG TECH INC's AS54600 network hosting 54.6% of the observed IPs. Additionally, some ARTEX-related servers were found to host information related to other attack and security tools, such as CyberStrikeAI, AdaptixC2, and GoPhish. However, this does not confirm that the same attacker used all these tools simultaneously or in a single attack process. Further temporal analysis is required to understand the relationship between these tools and the observed servers.

Oasis Security plans to continue tracking the creation and destruction cycles, infrastructure movements, ARTEX version changes, and potential connections with other attack frameworks. The company emphasizes that the rapid spread of AI-based penetration and attack automation frameworks, such as ARTEX and CyberStrikeAI, poses a significant threat. With approximately 360 ARTEX-related infrastructures and around 1,000 CyberStrikeAI-related servers observed, it is clear that AI-driven attack automation is becoming more prevalent. These tools enable attackers to automate reconnaissance, information gathering, vulnerability scanning, and attack path setting, allowing them to exploit existing vulnerabilities and tools at an unprecedented scale and speed. Kim Geun-yong, CEO of Oasis Security, stresses the importance of proactive threat intelligence to identify and respond to AI-based attack tools and related infrastructures before they are used in actual attacks. The company will continue to track and analyze new AI attack frameworks, C2 infrastructures, and exploit infrastructures using its AGATHA platform.
