News

Korean Version of Financial Hacking Tool 'ARTEX' Emerges, Detection Rules Also Released

Korean Version of Financial Hacking Tool 'ARTEX' Emerges, Detection Rules Also Released
▲ Korean version of ARTEX

A Korean version has emerged for "ARTEX," a Chinese-made, artificial intelligence (AI)-powered autonomous penetration testing tool that recently drew attention in connection with cyberattacks on the domestic financial sector.

As ARTEX, originally developed in Chinese, has been translated and shared in languages such as Korean and Japanese, its lower language barrier makes it easier to use for security research and legitimate penetration testing. However, concerns are also rising over the increased likelihood of malicious actors gaining access and the tool spreading.

Notably, the Korean version has drawn attention from the security industry by even including Sigma and Suricata detection rules to identify traces of ARTEX activity, which were absent in the original version.

According to the developer platform GitHub on October 7, a Korean version project of ARTEX named "artex-ko" has been made public.

ARTEX is an autonomous penetration testing program designed to connect with large language models (LLMs) so that AI agents can analyze targets, plan intrusion paths, and execute security tools.

A security industry expert, speaking on the condition of anonymity, said, "The translation and sharing of an AI-based penetration testing tool originally developed in Chinese into multiple languages such as Korean and Japanese indicates that interest and application scope for the tool are expanding beyond the Chinese-speaking sphere into various countries."

The expert added, "While translation into native languages lowers the language barrier, making it easier to utilize for security research or legitimate penetration testing, it is necessary to note that access for users with relatively less professional knowledge or malicious attackers also becomes easier, which could increase the potential for abuse and expand the scope of cyber threats."

In particular, materials related to detecting ARTEX activities, which were not present in the original Chinese version, were added to the Korean version.

The creator of the Korean version included Sigma detection rules, which are utilized to identify specific threat traces in security logs, as well as Suricata rules for network intrusion detection.

A security industry expert explained, "Because ARTEX allows AI to vary attack methods depending on the situation, there are limitations in viewing attack behaviors themselves as a single fixed pattern." The expert added, "However, if features that appear relatively fixed due to the program's structure—such as network communications or scanning processes—are regularized, they can serve as references in determining whether ARTEX is being used."

Sigma is a universal detection rule format designed to analyze logs collected from various security products in a standardized manner.

The rules added to the Korean version are also closer to a methodology that security personnel can leverage to detect ARTEX-related traces rather than a feature that blindly identifies ARTEX, according to the explanation.

The expert stated, "Since attackers can modify target strings or settings, it is difficult to say that ARTEX can be 100% detected with these rules alone. Still, they would be useful to some extent in detection when public tools are exploited without significant modifications."

However, the specific background behind why the developer of the Korean version additionally included detection-related materials not found in the original has not been confirmed.

(Photo: Captured from GitHub, Yonhap News)
※ Please note: This article was translated by AI and may contain errors.
Copyright Ⓒ SBS & SBSi. All rights reserved.
Copying, redistribution, and unauthorized use in AI training are strictly prohibited.

Most Read