Chinese Open-Source AI Agent Traced in Hacking of Korean Financial Firms | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker

Traces of an open-source artificial intelligence agent developed in China have been detected in a recent wave of hacking attacks targeting South Korean financial firms. A tool originally built to help companies and institutions find security weaknesses has been turned into a weapon for hackers.
According to The Wall Street Journal on the 6th, signs of ARTEX AI, an open-source AI agent created by a Chinese cybersecurity engineer, were found in cyberattacks that recently struck Korean financial companies.
ARTEX is an AI-based cybersecurity tool developed by Li Fuhua, a Chinese cybersecurity engineer. Rather than running on a single built-in AI model, it is designed to connect multiple large language models — including Anthropic’s Claude, OpenAI’s GPT and China’s DeepSeek — so they can be used as a single agent.
Hacking was not its original purpose. It was built to help companies and institutions inspect their own networks and identify security vulnerabilities. But because the source code is open and anyone can download and modify it free of charge, that openness appears to have been exploited.
ARTEX drew attention only recently. Last month it won a competition in China for agent-based AI systems used in cybersecurity attack and defense, earning recognition for its technical capabilities. Concerns that its ability to detect vulnerabilities and analyze attack paths could instead be used in actual crimes have now materialized.
ARTEX Traces in Attacks on Korean Financial Firms as Hackers Route Through Overseas IPs
The attacks were routed through internet addresses in multiple countries. Investigators believe the attackers passed through more than 20 IP addresses in about a dozen countries, including the United States, Japan and Germany, before striking domestic financial firms.
On some of the web servers used in the attacks, investigators also found a Chinese-language string reading “ARTEX-自主渗透試控制台.” On that basis, authorities are examining the possibility that ARTEX was used during the attacks. As of now, however, the identity of those behind the attacks has not been established.
The attacks are believed to have exposed the personal information of about 68,000 people, including customers and employees, at seven financial companies, among them major domestic banks. The leaked data is said to include sensitive financial details for some customers, such as annual income and personal loan limits. There are concerns the breach could lead to secondary damage, including voice phishing or illegal trading of personal data.
The Cyber Terror Investigation Unit of the Korean National Police Agency is investigating the circumstances and the source of the attacks, which were first detected last week. Financial regulators are also working to determine the scale of the damage while cooperating with overseas law enforcement agencies to track the attackers.
As the fallout spread, the government stepped in. President Lee Jae-myung told a Cabinet meeting that “speed is of the essence,” instructing the financial industry and relevant ministries to implement necessary security measures immediately.
After the case came to light, ARTEX’s developer added language to the tool’s user guidelines stating that it must not be used for malicious purposes such as unauthorized intrusion or data theft. But critics note that such guidelines alone are unlikely to prevent misuse, given that anyone can download, use and modify the source code of an open-source project.
Mun Chong-hyun, head of the security center at Genians, told the Journal that cybersecurity attacks using AI agents are increasing in South Korea and that the number is expected to rise worldwide as well.

