ARTEX AI-Linked Infrastructure Observed Scanning UK CNI: Discovery and Associated Services banner image
Blog
BCON COLLECTIVE

ARTEX AI-Linked Infrastructure Observed Scanning UK CNI: Discovery and Associated Services

By BCON Collective 9 October 2026 15 min read
On 28/09/2026, Bridewell BCON observed network scanning against a UK CNI customer from infrastructure exposing ARTEX, an open-source platform described by its developers as an AI-powered autonomous penetration-testing system. Our infrastructure tracking identified 65 unique IPs matching ARTEX discovery fingerprints. Follow-up analysis found additional offensive-security services on some of these hosts, including ToShell, CyberStrikeAI, Cobalt Strike, Gophish, and Adaptix. These findings place ARTEX-exposing infrastructure within activity affecting UK CNI and show its presence alongside established offensive tools.
Joshua Penny, Senior Threat Intelligence Analyst

Infrastructure Analysis and Tracking

We identified 65 IPs across 13 country locations and 35 ASNs, concentrated in the United States (29), China (12), and Hong Kong (7). The strongest address clustering was in 38.11.173.0/24 (8 IPs) and 38.11.221.0/24 (6), all under AS54600 with Cogent organisation labels. Tencent-associated AS45090 followed with 8 IPs in China.

IPASNOrgCountry
1.14.193.53AS45090Tencent cloud computing (Beijing) Co., Ltd.China
14.128.50.113AS152194CTG Server Ltd.Hong Kong
14.128.50.115AS152194CTG Server Ltd.Hong Kong
23.248.226.254AS138415RedLuff, LLCHong Kong
38.11.173.10AS54600Cogent Communications, LLCUnited States
38.11.173.18AS54600Cogent Communications, LLCUnited States
38.11.173.36AS54600Cogent CommunicationsUnited States
38.11.173.49AS54600Cogent Communications, LLCUnited States
38.11.173.54AS54600Cogent Communications, LLCUnited States
38.11.173.59AS54600Cogent Communications, LLCUnited States
38.11.173.69AS54600Cogent Communications, LLCUnited States
38.11.173.114AS54600Cogent Communications, LLCUnited States
38.11.221.7AS54600Cogent Communications, LLCUnited States
38.11.221.20AS54600Cogent Communications, LLCUnited States
38.11.221.54AS54600Cogent Communications, LLCUnited States
38.11.221.93AS54600Cogent Communications, LLCUnited States
38.11.221.107AS54600Cogent Communications, LLCUnited States
38.11.221.123AS54600Cogent Communications, LLCUnited States
38.54.16.112AS138915Kaopu Cloud HK LimitedSingapore
38.60.136.28AS154177Cogent Communications, LLCFrance
38.76.188.63AS401701Cogent Communications, LLCVenezuela, Bolivarian Republic of
38.244.50.120AS174NetLabUnited States
43.162.95.207AS132203ACEVILLE PTE.LTD.United States
45.32.20.49AS20473The Constant Company, LLCJapan
45.76.97.145AS20473Vultr Holdings, LLCJapan
45.149.154.125AS215727JOGCORP SASFrance
47.237.90.31AS45102Alibaba Cloud LLCSingapore
47.251.39.59AS45102Alibaba Cloud - USUnited States
49.235.52.47AS45090Tencent cloud computing (Beijing) Co., Ltd.China
64.118.131.167Not reportedBrown ArtUnited States
66.179.30.133AS399629BL NetworksUnited States
69.33.213.136AS3257GTTUnited States
82.29.129.54AS142036Hosteons Pte. Ltd.United States
82.157.129.205AS45090Tencent Cloud Computing (Beijing) Co., LtdChina
89.106.84.222215030Aspire HostingGermany
91.224.92.16AS209605UAB Host BalticLithuania
100.42.230.112AS5428880VPS.comUnited States
103.36.63.166AS134771Zhejiang zhi cloud information technology co., LTDChina
103.124.105.32AS142036Hosteons.com VPSUnited States
103.163.47.128AS58519Inner Mongolia Ruitong Network Technology Co., LtdChina
103.193.173.9AS132325; AS206300IPXO; LEMON TELECOMMUNICATIONS LIMITEDHong Kong
104.234.174.13AS134677Internet Utilities NA LLCIndia
106.13.196.61AS38365Beijing Baidu Netcom Science and Technology Co., Ltd.China
111.228.36.150Not reportedeleven street,No. 18 Institute of Jingdong headquartersChina
118.25.100.71AS45090Tencent Cloud Computing (Beijing) Co., LtdChina
118.193.39.134135377UCLOUD INFORMATION TECHNOLOGY (HK) LIMITEDHong Kong
119.45.105.71AS45090Tencent cloud computing (Beijing) Co., Ltd.China
122.51.183.32AS45090Tencent cloud computing (Beijing) Co., Ltd.China
124.221.46.59AS45090Tencent cloud computing (Beijing) Co., Ltd.China
129.28.104.75AS45090Tencent Cloud Computing (Beijing) Co., LtdChina
129.226.195.233AS132203Not reportedSingapore
130.94.43.244AS154177LIGHT NODE LIMITEDUnited States
137.220.151.95AS152194NTT Singapore Pte LtdSingapore
151.245.90.134AS31549Not reportedNetherlands
156.239.40.14400619AROSSCLOUD INC.United States
167.160.190.182AS36352HostPapaCanada
168.222.97.94Not reportedAir Products & Chemicals, Inc.United States
172.105.240.241AS63949LinodeJapan
182.16.62.130AS963Netsec LimitedHong Kong
186.244.245.13AS7738Globenet Cabos Submarinos America Inc.Brazil
189.24.77.148979NetLab Global - APBrazil
192.236.166.73AS36352HostPapaUnited States
198.44.170.40AS152705VpsQuan L.L.C.Hong Kong
207.57.126.196AS139659NTT America, Inc.United States
216.108.230.1526277ServerPoint.comUnited States


External reporting

Recently, Team Cymru S2 post shared a post on ARTEX.

Additional Services

In addition to ARTEX, BCON CTI analysed our host dataset to identify additional capabilities or services running on other ports, in order to add context into subplementary toolsets and new detection opportunities. Below is a summary of these findings, of which, all are tracked in our malicious infrastructure tracking platform.

IPASNOrgCountryPort / TransportAdditional Service / Lead
1.14.193.53AS45090Tencent cloud computing (Beijing) Co., Ltd.China3333/tcpGophish
1.14.193.53AS45090Tencent cloud computing (Beijing) Co., Ltd.China8089/tcpGophish-related certificate
38.60.136.28AS154177Cogent Communications, LLCFrance18081/tcpToShell C2
45.76.97.145AS20473Vultr Holdings, LLCJapan8080/tcpStrix report interface
103.163.47.128AS58519Inner Mongolia Ruitong Network Technology Co., LtdChina8081/tcpCyberStrikeAI
118.25.100.71AS45090Tencent Cloud Computing (Beijing) Co., LtdChina8551/tcpCobalt Strike Beacon
118.25.100.71AS45090Tencent Cloud Computing (Beijing) Co., LtdChina50050/tcpCobalt Strike C2
119.45.105.71AS45090Tencent cloud computing (Beijing) Co., Ltd.China4321/tcpAdaptix C2
137.220.151.95AS152194CTG Server Ltd.Singapore3333/tcpGophish
137.220.151.95AS152194CTG Server Ltd.Singapore8888/tcpCobalt Strike Beacon
137.220.151.95AS152194CTG Server Ltd.Singapore9999/tcpCobalt Strike Beacon
192.236.166.73AS36352HostPapaUnited States8080/tcpCyberStrikeAI
192.236.166.73AS36352HostPapaUnited States8090/tcpCyberStrikeAI
  • ToShell is a lightweight command-and-control (C2) framework with a team server, web console, and cross-platform agents. It supports payload generation, session management, and remote task execution.
  • CyberStrikeAI is an open-source AI-assisted security-testing platform that coordinates security tools and agent workflows. Its web interface supports managing testing activity and reviewing results.
  • Cobalt Strike is a commercial adversary-simulation platform used by red teams to emulate attacker activity. Its Beacon component receives tasks from a team server and returns execution results.
  • Gophish is an open-source phishing-simulation framework for creating campaigns, sending test emails, and tracking recipient responses. A Gophish-labelled certificate alone does not establish that a Gophish instance is running.
  • Adaptix C2 is an extensible post-exploitation and adversary-emulation framework for penetration testers. It combines a team server, operator client, and agents for managing remote sessions.
  • Strix is an open-source AI penetration-testing tool for identifying and validating application vulnerabilities. The observed Strix-labelled report page does not establish that this specific project or a running Strix agent is present.


Assessment

For CNI defenders, the immediate value of these findings is a set of infrastructure leads to investigate alongside scanning of exposed systems. Review connections from the identified IPs to determine which services were reached, whether requests attempted exploitation, and whether any activity progressed to authentication or endpoint execution. Distinguishing routine probing from activity requiring response helps focus investigation on systems supporting essential services. The observed scanning alone does not establish compromise.

The additional services give those investigations useful context. Some ARTEX-discovered IPs also expose interfaces or signatures associated with phishing, remote control, and post-exploitation tools. That makes them relevant leads for correlating network and endpoint evidence, but it does not show that all services share an operator.

The broader observation is that AI-assisted security-testing platforms are appearing alongside established offensive tools in internet-facing infrastructure. For defenders, this supports tracking AI-assisted tooling through the same evidence used for other activity: source infrastructure, requests against exposed services, process execution, and subsequent connections.

Stop Reacting. Start Hunting.

Bridewell’s threat-led MDR service combines world-class analysts with proprietary intelligence to protect your critical infrastructure and assets 24/7.

BCON ICON

BCON Collective

Cyber Threat Intelligence Team

Real-world incident response insights from our cyber security experts.