Security & privacy

AI pentesting tools ARTEX and SCARLET LOOP drive new financial attacks

CrowdStrike and ZenoX report that attackers used open-source AI agents ARTEX and SCARLET LOOP to breach South Korean banks and Brazilian loyalty platforms in late 2026.

A robotic hand using a digital tool to break a glass security shield.
Illustration generated for this article

In late September and early October 2026, threat actors deployed artificial intelligence agents to breach financial institutions in South Korea and Brazil. CrowdStrike Intelligence identified a campaign using the ARTEX penetration testing tool against Korean firms, while ZenoX uncovered the SCARLET LOOP platform targeting Brazilian accounts. Both operations resulted in significant data exfiltration and credential theft, marking a shift toward autonomous, AI-driven cybercrime.

What happened

CrowdStrike discovered the South Korean campaign after identifying open directories on a Hong Kong-based IP address. These directories exposed Claude Code session histories, memory files, and configuration data for ARTEX, an open-source agentic penetration testing tool developed by Autumn-27 in China. The attacker operated from the IP address 38.244.50[.]120, which hosted the ARTEX instance used in the intrusions. While no specific group has been attributed to the attacks, evidence suggests a Chinese-speaking operator motivated by financial gain.

Simultaneously, ZenoX detailed the activities of SCARLET LOOP, a platform orchestrated by a Portuguese-speaking actor. This operation targeted Brazilian loyalty programs, corporate incentives, and gift card platforms. The attackers used stolen credentials from infostealer logs and data leaks to hijack accounts at scale. Analysis of an internet-exposed server revealed that the group tested over 12 million credentials, successfully validating nearly 12,000 across thousands of domains.

Following the misuse of their software, Autumn-27 announced that ARTEX would move to a closed-source model. The developers stated that the tool was intended for authorized security research and learning, not malicious activity. They confirmed that no further versions or maintenance support would be released to prevent additional abuse.

How it works

The ARTEX system operates as a multi-agent autonomous penetration framework driven by large language models (LLMs). In the observed campaign, the attacker configured ARTEX to use DeepSeek v4.1-flash as its primary backend, supplemented by Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6. The operator likely accessed these models through an API reseller. The agent autonomously navigated systems, identified vulnerabilities, and exfiltrated data, while also querying Claude for information on selling breached data via Telegram groups.

SCARLET LOOP employs a more complex, multi-stage automation pipeline. It begins with target discovery using OpenAI's GPT-5.6 to generate search queries and GPT-5.5 to classify high-value targets. For login execution, an AI agent drives an instrumented Firefox browser that spoofs digital fingerprints like canvas, WebGL, and geolocation to bypass anti-bot defenses. The agent uses DeepSeek-V4-Pro, Claude Opus 4.6, and other models to map login surfaces and fill forms without human supervision.

To optimize costs, SCARLET LOOP features an "AUTO Mode" that removes the LLM from the loop after successful logins on a familiar domain. As ZenoX noted, model reasoning is expensive and slow, so the platform pays for intelligence only once per target. This allows the system to scale credential stuffing efficiently, testing millions of combinations while minimizing token usage.

Key details

  • The ARTEX campaign targeted South Korean financial organizations from late September to early October 2026.
  • ARTEX used DeepSeek v4.1-flash as its main LLM, with GLM-5.3 and Grok 4.6 as supplements.
  • SCARLET LOOP tested 12,277,358 credentials, validating 11,832 across 3,968 domains.
  • The SCARLET LOOP agent uses 46 automation tools and outsources captcha solving to bypass detection.
  • Autumn-27 has closed the source code for ARTEX following its use in unauthorized attacks.
  • Attackers used Telegram channels, including one linked to the handle "@YY520CN", to coordinate data sales.

Why it matters

These incidents demonstrate that open-source AI security tools are being weaponized with minimal modification. Developers and security leads can no longer assume that penetration testing frameworks are safe by default. The ease with which an operator configured ARTEX using public APIs and open directories highlights the risk of exposed development environments. If configuration files and session histories are left accessible, attackers can replicate and scale these operations rapidly.

For engineering teams building AI agents, the SCARLET LOOP architecture offers a troubling blueprint for efficiency. By combining LLM reasoning for novel tasks with simple automation for repetitive ones, attackers reduce costs while maintaining high success rates. This hybrid approach allows them to adapt to new login forms and security measures dynamically, making traditional static defenses less effective. Organizations must anticipate adversaries who can reason through unfamiliar interfaces autonomously.

What you can do

  • Audit all public-facing directories and servers to ensure no configuration files, session histories, or API keys are exposed.
  • Implement strict access controls for any AI agents or penetration testing tools used within your infrastructure.
  • Monitor for unusual API usage patterns, particularly from resellers or unexpected geographic locations.
  • Enhance bot detection mechanisms to identify spoofed browser fingerprints such as canvas, WebGL, and viewport data.
  • Review and rotate credentials regularly, assuming that stolen logs from third-party breaches may already be in circulation.
  • Restrict the capabilities of AI agents to specific, authorized assets to prevent unintended lateral movement or data exfiltration.

Tools from the Bytechap store

Keep reading

All stories