AI Automated Translation.

Font Size

Share

Korean version of financial sector hacking AI attack tool 'ARTEX' released… "For defensive purposes"

Korean version of financial sector hacking AI attack tool 'ARTEX' released… "For defensive purposes"

Actual UI after Korean localization /Photo=Screenshot from GitHub
Actual UI after Korean localization /Photo=Screenshot from GitHub

A Korean-language version of ARTEX, an artificial intelligence (AI) penetration testing tool reportedly used in recent financial sector hacking incidents, has been made public.

On the 7th, a project named 'artex-ko,' which is the Korean version of ARTEX, was released on the developer platform GitHub.

ARTEX is an open-source program designed to allow AI agents to analyze attack targets, plan penetration paths, and execute security tools with minimal human intervention by leveraging large language models (LLMs).

In this process, it accumulates asset information such as newly discovered servers and systems, along with vulnerabilities, and independently determines the next stage of attack methods.

The original project, 'Autumn-27/ARTEX,' was released by a Chinese developer and has provided a Chinese-based interface and documentation. The Korean version modifies the output to display web screens visible to users, vulnerability detection results, summaries, final reports, and conversational responses in Korean.

This Korean version provides Sigma rules for identifying ARTEX activity traces and 'Suricata' rules used for network intrusion detection. All of these rules are not present in the original version.

Photo=Screenshot from GitHub
Photo=Screenshot from GitHub

While the translation and distribution of ARTEX, originally developed in Chinese, into Korean has significantly improved accessibility, concerns are also growing that it could be easily misused.

As if aware of this, the repository for the Korean version includes a notice warning about security and misuse, alongside reports that the original ARTEX was used in recent personal information leakage attacks targeting domestic financial institutional investors.

The warning states, "ARTEX is a powerful autonomous attack tool capable of independently executing the entire attack process—from reconnaissance to penetration and data exfiltration—with almost no human intervention. Consequently, the damage caused by misuse is equally significant." It emphasized, "The purpose of releasing the Korean version is not to facilitate attacks. The aim is to help defenders understand how such autonomous AI attacks operate, and to build their capabilities to detect and block them."

"This article was translated using AI and may differ slightly from the original."