▲ ATMs installed across Seoul
“ARTEX AI,” which has reportedly been used to hack South Korean financial institutions, is a cybersecurity tool developed in China, but hackers appear to have exploited it to attack banks, according to The Wall Street Journal (WSJ).
On the 6th (local time), the WSJ highlighted ARTEX, an open-source cybersecurity tool from China.
ARTEX is an open-source AI agent developed by Li Puhua, a Chinese cybersecurity engineer who goes by the nickname “Autumn.”
While the agent itself is not an artificial intelligence model, the tool allows users to call upon various other AI models and utilize them as if they were team members.
For example, users can bring in models such as Anthropic’s Claude, OpenAI’s GPT, and China’s AI model DeepSeek to use them on the ARTEX platform.
The developer originally created this tool for cybersecurity purposes to help organizations identify network vulnerabilities, but hackers appear to have instead exploited it to launch security attacks using AI models.
Such misuse was possible because the tool was released as open-source, allowing anyone to download it for free, modify it, and use it for their own purposes.
Following reports of the bank hacking incident, ARTEX specified in its user guidelines that it must not be used for malicious purposes such as unauthorized cyber intrusion or data theft.
However, this is merely a declarative measure and does not serve as a fundamental means to prevent users with criminal intent from exploiting it for cyberattacks.
Moon Jong-hyun, head of the Genians Security Center, a South Korean cybersecurity analytics firm, said, “Cybersecurity attacks utilizing AI agents are increasing in South Korea,” and added, “The number is expected to grow globally as well.”
ARTEX previously drew attention by winning a competition for agent-based AI systems for cyber offense and defense held in China last month.
The recent attack on South Korean financial institutions was carried out through some 20 IP addresses across more than 10 countries, including the United States, Japan, and Germany, in order to evade tracking.
The identities of the suspects have not yet been determined, but Chinese character strings reading “ARTEX-自主渗透試控制台” were identified on some of the web servers utilized in the attack.
(Photo: Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Click Here For The Original Source.
