A Chinese-developed cybersecurity AI agent, 'ARTEX AI,' has been implicated in hacking South Korean financial institutions. The open-source nature of this AI, designed for cybersecurity, raises concerns that it could be misused as a tool for hackers.
On October 6, The Wall Street Journal highlighted the development, functionality, and potential misuse of ARTEX in light of the recent hacking incidents involving South Korean financial firms.
According to the report, ARTEX is an open-source AI agent created by Chinese cybersecurity engineer Li Puhua, who goes by the nickname 'Autumn.' Being open-source, it can be freely downloaded and modified by anyone.
ARTEX is not a single AI model but an agent system that utilizes multiple AI models to perform cybersecurity tasks. Users can select from various AI models, including Anthropic's Claude, OpenAI's GPT, and China's DeepSeek, through ARTEX.
Designed to automate penetration testing, ARTEX uses these AI models to identify cybersecurity vulnerabilities. It autonomously explores networks and software for weaknesses and plans pathways to reach its targets. The AI can conduct exploration, execution, and result analysis without requiring constant user commands.
ARTEX recently won a cybersecurity competition in China, where it demonstrated its attack and defense capabilities among agent-based AI systems, sponsored by several tech companies.
However, evidence has emerged that hackers utilized ARTEX in the recent South Korean financial hacking incidents. Authorities in South Korea are investigating the possibility that ARTEX was used to breach banking systems and steal customer and employee information.
Following the revelation of the hacking incidents, the ARTEX team updated its usage guidelines to prohibit illegal and malicious applications of the tool, including unauthorized access and data theft.
Concerns about AI agents accessing the internet and external systems without human intervention and being exploited for cyberattacks are becoming a reality globally.
Last year, Anthropic claimed that hackers supported by the Chinese government automated intrusions into approximately 30 targets worldwide, including businesses and foreign governments, using its AI technology. Reports have also surfaced of OpenAI and Google's AI agents accessing Australian government websites and other corporate systems.
Jamie Dimon, CEO of JPMorgan Chase, stated in an interview with Bloomberg TV on October 6, "AI has created vulnerabilities we did not know about," adding that the negative aspects of AI, such as agents and myths, are indeed concerning and pose real risks. However, he noted that he would not overreact to the existential risks posed by AI, stating, "We are rolling up our sleeves and working to address the issues."
* This article has been translated by AI.
Copyright ⓒ Aju Press All rights reserved.
