
AI-generated summary
ARTEX, an open source cybersecurity tool developed in China, was originally created to help identify network vulnerabilities, but hackers appear to have abused it to carry out security attacks targeting Korean financial companies.
(San Francisco = Yonhap News) Correspondent Kwon Young-jeon = 'ARTEX AI', which was revealed to have been used to hack Korean financial companies, is a cybersecurity tool developed in China, but hackers appear to have abused it to attack banks, the Wall Street Journal (WSJ) reported.
On the 6th (local time), WSJ highlighted China's open source cyber security tool, ARTEX.
ARTEX is an open AI agent developed by Chinese cybersecurity engineer Li Puhua, who goes by the nickname 'Autumn'.
Although this agent is not an artificial intelligence (AI) model itself, this tool allows you to load other AI models and use them as if they were team members.
For example, Antropic's Claude, OpenAI's GPT, and China's AI model DeepSeek are imported and used on ARTEX.
The developer originally created this tool for cybersecurity purposes to help various organizations identify network vulnerabilities, but hackers appear to have abused it to carry out security attacks using AI models.
Such abuse was possible because the tool was open and anyone could download it for free, modify it for their own purposes, and use it.
After the bank hacking incident was reported, ARTEX specified in its user guidelines that it should not be used for malicious purposes such as unauthorized cyber intrusion or data theft.
However, this is only a declarative measure and is not a means to fundamentally prevent cyber attacks and other abuses by users who wish to commit crimes.
“Cybersecurity attacks using AI agents are increasing in Korea,” said Jonghyun Moon, director of Genius Security Center, a Korean cybersecurity analysis company. “The number is expected to increase globally as well.”
ARTEX attracted attention by winning the agent-type AI system competition for cyber security attack and defense held in China last month.
This attack on a Korean financial company was carried out through 20 IP addresses in 10 countries, including the United States, Japan, and Germany, to avoid tracking.
The identity of the suspect has not yet been identified, but the Chinese character string 'ARTEX-自主渗透試控制台' was confirmed on some of the web servers used in the attack.
AI outlook — possibilities, not facts
Cybersecurity attacks using AI agents are expected to increase in Korea
Likely · Within months

It was confirmed through analysis by security company Oasis Security that two large domestic churches suffered cyber attacks and a large amount of data, including personal information of members, donation records, and internal documents, was leaked. It is analyzed that the attacker used a web shell and account information to infiltrate the internal system.

Over the past five years, the share of major overseas telecommunications carriers, such as Google and Netflix, in domestic Internet traffic has increased to 47%. As foreign operators took the top 1 to 3 positions, the debate over network usage fees reignited.

Minister of Science and ICT Bae Kyung-hoon announced during the National Assembly audit that the AI model applied to the government business AI platform will be replaced with the second model of the independent foundation model (Dokpamo). This is a measure taken in response to criticism that the government-wide AI platform included Chinese AI models.

The passwords of over 75,000 Google Workspace accounts used by schools and educational institutions in the Daejeon area were changed without permission, and the Daejeon Metropolitan Office of Education took measures to suspend use and change them again.

DigitalX announced that it has launched a new app equipped with a generative artificial intelligence chatbot, the first domestic virtual asset exchange. Users can obtain market information and place orders by asking questions in natural language, and there is also a function to switch between Lite and Pro modes and a reward event when missions are achieved.

It was confirmed that the attacker IP used in the recent hacking incident at a major financial company also attempted to access Kakao Bank, K Bank, and Toss Bank servers several times, but it was detected and blocked by the security system, so no actual damage occurred, the financial industry announced.