---
title: AI hacking tool ARTEX infrastructure found in South Korea
url: https://www.dataloco.com/en/ai-hacking-tool-artex-infrastructure-found-in-south-korea
published: 2026-10-06T20:24:26+00:00
language: en
section: Security
source: https://zdnet.co.kr/view/?no=20261004170058
organizations: Oasis Security, PEG TECH INC, Tencent
publisher: Dataloco
---

# AI hacking tool ARTEX infrastructure found in South Korea

Cybersecurity firm Oasis Security has identified 500 instances of ARTEX infrastructure on the internet, including four servers located in South Korea. This discovery follows reports of cyberattacks against major domestic financial institutions, where traces of the tool were reportedly found in web server data. The findings indicate a significant expansion of AI-based penetration testing systems in the global threat landscape.

ARTEX is an open-source, autonomous penetration testing system that utilizes large language models. It is designed to allow security professionals to automate the process of asset discovery, vulnerability analysis, and security verification. The system features a Go-based backend and a web frontend, and it is configured by default to serve its web interface on TCP port 8787. While intended for authorized security testing, its open-source nature allows anyone to deploy it, creating a risk that attackers could use it to automate reconnaissance and attack preparation.

Oasis Security analyzed data collected between September 23 and October 3 using its AGATHA platform. After removing duplicate observations, the firm identified 359 unique IP addresses associated with ARTEX. Of these, 334 instances, or approximately 93 percent, were observed using the default TCP 8787 port. The analysis also revealed 392 distinct service exposure patterns based on IP and port combinations. The geographic distribution of these servers was heavily concentrated, with the United States hosting 236 instances, China 53, and Hong Kong 39. Together, these three regions accounted for 91.4 percent of the total observed infrastructure.

Network analysis showed a significant concentration of ARTEX infrastructure on specific hosting providers. The AS54600 network, operated by PEG TECH INC, hosted 196 unique IP addresses, representing 54.6 percent of the total. A substantial number of instances were also found on the AS45090 network, which is associated with Tencent. This distribution suggests that the infrastructure is not evenly spread but is instead clustered within specific virtual private server and hosting networks. The presence of these servers in various countries does not necessarily indicate the location of the attackers, as cloud and virtual private server services allow for the use of infrastructure in unrelated regions.

In addition to ARTEX, the analysis detected information related to other cyber tools on some of the same servers. These included CyberStrikeAI, AdaptixC2, GoPhish, and Acunetix. However, the firm noted that the co-occurrence of these tools does not definitively prove that a single attacker used them simultaneously or in a combined operation. Further time-series analysis is required to determine if the servers were reused at different times or if multiple services were deployed on the same infrastructure. The firm plans to continue tracking the lifecycle of these servers and their association with other attack frameworks.

Oasis Security also reported that it is tracking approximately 1,000 servers associated with CyberStrikeAI, another AI-based attack automation tool. The firm emphasized that the rapid proliferation of these AI-driven frameworks represents a shift in the threat landscape. Unlike traditional scanners that repeat predefined tasks, these systems analyze collected information to decide on next steps and call necessary tools. This capability allows attackers to automate significant portions of the attack process, including reconnaissance and vulnerability exploitation, without needing to develop new techniques. The firm stated that the scale of these deployments suggests that attackers may soon be able to scan and attack a larger number of systems in a shorter time, necessitating proactive threat intelligence measures to identify and respond to such infrastructure before it is used in actual attacks.

## This story in other languages

- [Português (Brasil)](https://www.dataloco.com/pt-br/quatro-infraestruturas-da-ferramenta-de-hacking-com-inteligencia-artificial-artex-sao-detectadas-na-coreia)
