China’s AI attack tool ARTEX AI now detected in 600 global IP addresses.

A tool named “ARTEX AI,” developed by Chinese cybersecurity engineers, has recently surfaced in the hacking incidents targeting South Korean financial institutions like Shinhan Bank. The latest investigation reveals that ARTEX activity has been detected in approximately 600 network IP addresses globally.

Originally designed for cybersecurity testing, this AI tool has garnered attention due to the possibility of being repurposed for automated network attacks.

According to reports from Yonhap News Agency, ARTEX has not only appeared in the recent hacking incidents involving multiple South Korean financial institutions. AhnLab Security Center (ASEC) in South Korea published an analysis of the infrastructure of ARTEX AI on GitHub, finding traces of ARTEX on approximately 600 IPs globally, with some servers also running another AI attack security platform called “CyberStrikeAI.”

ASEC stated that since ARTEX AI is an open-source tool that anyone can create, it is difficult to attribute all identified IPs to a single infrastructure operated by the same organization or specific threat actors. These servers may include normal usage by Red Teams, penetration testers, and cybersecurity researchers.

ARTEX is not an AI model but a set of open-source AI autonomous penetration testing systems. It is based on large language models and utilizes multiple AI agents to carry out tasks such as vulnerability identification, validation, and attack process planning and execution.

Most of the project documentation and user interface of ARTEX are written in Chinese, leading to speculation of its potential association with the Chinese cybersecurity community. However, as ARTEX is a publicly available open-source tool, it is challenging to attribute related IPs to Chinese hackers or specific attack organizations solely based on detecting ARTEX traces.

As of October 6, South Korean financial regulatory authorities have identified 28 IPs related to recent hacking incidents involving South Korean financial institutions, located in the United States, Japan, and ten other countries. Officials believe hackers may exploit ARTEX to identify system vulnerabilities in financial institutions and gain access to customer and employee data.

During the analysis process, ASEC also discovered that some IPs were simultaneously running another tool called “CyberStrikeAI.” This open-source AI attack security platform offers various features, including multiple AI agents collaboration, various cybersecurity tools, attack chain analysis, and WebShell and C2 (command and control) management.

ASEC emphasizes that both ARTEX AI and CyberStrikeAI are public tools, and even if they appear on the same IP, it cannot be assumed that they are operated by the same hacker or part of the same attack. The repeated appearance of various AI security tools in real network environments indicates the increasing potential widespread use of these frameworks.

AI autonomous agents are lowering the technical barriers to network attacks. ASEC believes that such tools enable attackers with lower technical capabilities to execute complex tasks that previously required skilled professionals. For experienced hackers, these tools can further enhance attack speed and scale.

While AI may not create new attack methods, it can significantly alter the “efficiency” and “cost” of attacks. This is why the South Korean bank hacking incident has attracted international attention.

The Wall Street Journal noted that ARTEX can utilize different AI models such as OpenAI, Anthropic, and DeepSeek, allowing AI agents to search for vulnerabilities and plan attack routes with minimal human intervention.

Experts anticipate that AI-driven network attacks may increase globally in the future. This concern is not merely theoretical. In 2025, Anthropic disclosed a case involving state-level Chinese hackers conducting network espionage activities. Anthropic estimated that attackers utilized their AI tool called Claude to carry out attacks on approximately 30 institutions, with 80% to 90% of tactical work autonomously performed by AI, including reconnaissance, vulnerability discovery, intrusion, and data theft.

Both the ARTEX incident in South Korea and the global scenario highlight a larger trend: AI agents are transitioning from “assisting human hackers” to “replacing humans in performing certain attack tasks.” This implies that genuine global cybersecurity risks may not stem from a single Chinese AI tool but rather from the proliferation of such autonomous AI attack tools, presenting a potential threat to governments, businesses, or individuals worldwide.

The risk of AI hackers is swiftly reflected in the South Korean stock market. On October 6, several cybersecurity stocks in South Korea experienced significant increases, with AhnLab rising by 15.58%, Genians by 20.83%, Sands Lab by 30%, and RaonSecure by 29.98%, touching their daily upper limits.

Analysts attribute these stock surges to the consecutive hacking incidents targeting financial institutions and the potential use of AI in automated attacks, leading the market to anticipate increased cybersecurity expenditure by governments and businesses, thus garnering investor attention.