ARTEX developer ends public releases after data theft abuse
AI-generated image

ARTEX developer ends public releases after data theft abuse

ARTEX misuse in data theft at South Korean financial firms prompted its developer to end public releases, as researchers detail another AI account attack.

ARTEX, an artificial intelligence (AI) tool for authorized security testing, is being withdrawn from public development after CrowdStrike Intelligence linked its misuse to data theft at South Korean financial organizations. According to CrowdStrike, the campaign ran from late September to early October 2026. Its findings describe attackers combining automated testing software with AI models, while a separate investigation by ZenoX documents AI-assisted account hijacking.

CrowdStrike discovered the ARTEX activity through open directories, folders accessible over the internet, at a Hong Kong-based internet protocol (IP) address, a network location. Those folders exposed Claude Code session histories, Claude memory files containing retained context, and ARTEX configuration files containing operating settings. The material provided visibility into the operator's infrastructure and interactions with AI services. The report does not name the affected financial organizations or specify the amount of data stolen.

Developed in China by Autumn-27, ARTEX was released as open-source software, meaning its source code was publicly available. It uses multiple AI agents, software components that perform tasks, to automate penetration testing, the authorized search for security weaknesses. Large language models (LLMs), AI systems that interpret and generate language, drive that process. CrowdStrike reported that an attacker used the tool alongside LLMs outside its intended authorized setting.

The Claude Code records indicated a two-server arrangement. CrowdStrike described the Hong Kong address as the campaign's central infrastructure, with a separate address, 38.244.50[.]120, hosting the ARTEX instance suspected of carrying out the South Korean attacks. That instance used DeepSeek v4.1-flash as its main model, supplemented by Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6. The researchers suspect the operator obtained DeepSeek access through xcai[.]pro, which they described as a likely reseller of LLM application programming interface (API) access, a way for software to send requests to a model.

CrowdStrike has not assigned the campaign to a known attacker or group. It suspects a Chinese-speaking operator seeking financial gain, but that assessment does not establish the person's identity. In addition to ARTEX work, the exposed sessions included requests asking Claude where stolen Korean breach information is typically sold and for help locating Korean data-sales groups on Telegram, a messaging service. These requests indicate an interest in selling information, not proof that a sale occurred.

One prompt contained the Telegram username @YY520CN and the name YY. The same username appeared in other sessions involving vulnerability research on a Telegram-based NFT gift marketplace, where NFT means non-fungible token, a digital token representing a distinct item. CrowdStrike considered the personal details likely to relate to the operator, but explicitly said the available evidence could not conclusively connect them to the person responsible.

Autumn-27 responded to the abuse by announcing that ARTEX would become closed source, with its code no longer publicly available, and that development would stop. The developer said there would be no further versions or maintenance support. Autumn-27 denied involvement in the malicious attacks and said the misuse contradicted the project's purpose: learning, research and security testing of assets for which enterprises and organizations had authorization. For legitimate users, the concrete consequence is an end to promised updates and support, not a reported fix for a specific vulnerability.

Separately, Brazilian cybersecurity company ZenoX described an automated platform operated by a financially motivated, Portuguese-speaking actor it calls SCARLET LOOP. This system performs credential stuffing, trying stolen username-and-password combinations on websites, and account takeover, gaining control of someone else's account. ZenoX said the platform automates the workflow from choosing victims to attempting access with credentials taken from data leaks and infostealer logs, records produced by malware that steals information.

Its four-stage process starts with AI-assisted discovery and assessment of valuable targets, primarily Brazilian loyalty, corporate incentives and gift card platforms. It then obtains credentials for each target and attempts logins through an AI-controlled browser designed to evade automated-activity checks. Finally, it sends successful credentials to a private Telegram channel, with a success marker followed by the website address and username-and-password pair.

ZenoX reported that OpenAI's GPT-5.6 generates specialized search queries to locate company authentication pages, where users sign in, within a chosen sector. GPT-5.5 classifies and rates the targets. The browser agent uses DeepSeek-V4-Pro and DeepSeek-V4-Flash. The configuration also includes Anthropic's Claude Opus 4.6, Google Gemini 2.5 Flash and GLM-5.1, plus Google's gemma-4-26B-A4B running locally at 127.0.0[.]1:1237, an address and connection point on the same machine.

In a report shared with The Hacker News, ZenoX described an LLM agent with 46 automation tools controlling a modified Firefox browser. It falsifies browser characteristics used to recognize visitors, including canvas and WebGL graphics information, time zone, language, location and viewport, the visible browser area. It also uses an external service to solve CAPTCHAs, challenges intended to distinguish people from automated software. The agent locates login pages, fills forms and evaluates the outcome. During discovery and login, ZenoX said it works without step-by-step supervision, adapting to unfamiliar forms, identifying security weaknesses and generating tailored automation.

The platform's AUTO Mode removes the AI model from login attempts after a set number of successful logins on one domain, a website's internet name. It then relies on the automation already established, returning to AI when it encounters an unfamiliar form. ZenoX explained that this reduces the time and cost of model reasoning and saves tokens, the units used to measure model input and output. Analysis of the platform's internet-exposed server showed 12,277,358 credentials tested, with 11,832 classified as valid across 3,968 domains. Those figures describe tested credentials and classifications, not a confirmed count of individual victims.

For website owners and IT teams, the reports identify two distinct concerns: stolen organizational data and automated abuse of customer logins. Neither report establishes a particular hosting or WordPress flaw. AEU-I's security-first IT, infrastructure and consulting services are relevant to businesses seeking help reviewing their security arrangements, rather than a demonstrated protection against either reported campaign. The evidence remains attributed to CrowdStrike and ZenoX, and th

How to Protect Yourself

  1. Use your password manager to create a different password for every website, especially financial, loyalty and gift card accounts.
  2. Turn on two-step verification in each account's security settings so a stolen password alone is not enough to sign in.
  3. Check recent sign-ins and reward or gift card transactions, and report any activity you do not recognize to the service.
  4. Ask your website provider to check that configuration files and saved work sessions cannot be opened by visitors.
  5. If your business uses ARTEX for authorized testing, ask your IT team to review its continued use because its developer has ended future releases and maintenance.

Terms Explained

  • penetration testing An authorized attempt to find security weaknesses before criminals exploit them.
  • large language models AI systems trained to interpret and generate language in response to requests.
  • open-source software Software whose underlying code is publicly available to inspect.
  • credential stuffing Trying stolen usernames and passwords on websites to find accounts they can unlock.
  • account takeover Someone gaining unauthorized control of another person's account.
  • infostealer logs Records of passwords and other information collected by malicious software.
  • CAPTCHAs Completely Automated Public Turing tests to tell Computers and Humans Apart are website challenges intended to check whether a visitor is human.

Related AEU services