
A Korean-language version of ARTEX, an artificial intelligence (AI) penetration testing tool reportedly used in recent financial sector hacking incidents, has been made public.
On the 7th, a project named 'artex-ko,' which is the Korean version of ARTEX, was released on the developer platform GitHub.
ARTEX is an open-source program designed to allow AI agents to analyze attack targets, plan penetration paths, and execute security tools with minimal human intervention by leveraging large language models (LLMs).
In this process, it accumulates asset information such as newly discovered servers and systems, along with vulnerabilities, and independently determines the next stage of attack methods.
The original project, 'Autumn-27/ARTEX,' was released by a Chinese developer and has provided a Chinese-based interface and documentation. The Korean version modifies the output to display web screens visible to users, vulnerability detection results, summaries, final reports, and conversational responses in Korean.
This Korean version provides Sigma rules for identifying ARTEX activity traces and 'Suricata' rules used for network intrusion detection. All of these rules are not present in the original version.

While the translation and distribution of ARTEX, originally developed in Chinese, into Korean has significantly improved accessibility, concerns are also growing that it could be easily misused.
As if aware of this, the repository for the Korean version includes a notice warning about security and misuse, alongside reports that the original ARTEX was used in recent personal information leakage attacks targeting domestic financial institutional investors.
The warning states, "ARTEX is a powerful autonomous attack tool capable of independently executing the entire attack process—from reconnaissance to penetration and data exfiltration—with almost no human intervention. Consequently, the damage caused by misuse is equally significant." It emphasized, "The purpose of releasing the Korean version is not to facilitate attacks. The aim is to help defenders understand how such autonomous AI attacks operate, and to build their capabilities to detect and block them."