WORLD

Chinese AI tool exploited in South Korean bank hacks, WSJ reports

by
Yu Hye-rim
Published : Oct. 7, 2026 - 08:07:46
    • Copy Completed!

View Korean Original

ARTEX, developed by a Chinese cybersecurity engineer, was designed to identify network vulnerabilities but was turned against financial institutions; its developer added warnings against malicious use after the bank hacking incidents came to light

ATM machines at commercial banks in Seoul. [Herald DB]
ATM machines at commercial banks in Seoul. [Herald DB]

A Chinese-developed AI cybersecurity tool called ARTEX AI was exploited in a series of hacking attacks against South Korean financial institutions, with a tool built for defense repurposed as a weapon, foreign media reported.

The Wall Street Journal reported Tuesday (local time) that the tool, originally designed to scan institutional networks for vulnerabilities, appears to have been turned against banks.

The Herald Business was first to report that investigators at the Financial Security Institute had found traces of ARTEX during their probe into the hacking incidents, amid questions over whether AI had been used in the attacks.

According to the Wall Street Journal, ARTEX is an open-source AI agent developed by Li Puhua, a Chinese cybersecurity engineer who goes by the alias "Autumn." It is not a standalone AI model but is designed to call on multiple models — including Anthropic's Claude, OpenAI's ChatGPT and China's DeepSeek — and deploy them like members of a team.

While the tool was built to identify network vulnerabilities within organizations, hackers appear to have weaponized it to carry out AI-assisted attacks. Its nature as a freely downloadable, open-source tool that anyone can modify for their own purposes is a key factor behind its susceptibility to misuse.

After the bank hacking incidents were reported, ARTEX added language to its user guidelines explicitly prohibiting use for malicious purposes such as unauthorized intrusion or data theft. However, such guidelines alone are widely regarded as insufficient to prevent criminal exploitation.

The attacks targeting South Korean financial firms were routed through more than 20 IP addresses across over 10 countries, including the United States, Japan and Germany — a tactic used to evade tracing. Chinese-language strings containing the ARTEX name were found on some of the web servers used in the attacks. The identity of the suspect has not yet been determined.


forest@heraldcorp.com
This content was produced with the assistance of AI translation services.

MOST READ