Threat reportThreat IntelligenceTL-2026-3008

Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool to Target South Korean Financial Organizations

highACTIVE

Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool (TL-2026-3008) is a high-severity tracked intrusion set, first published 2026-10-07. It has no confirmed attribution, affects Shinhan Bank M Shinhan mobile portal (loan officer / broker, maps to 8 MITRE ATT&CK techniques (T1078, T1090, T1110.004), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
8MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-3008

Threat ID
TL-2026-3008
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
finance, banking
Target regions
south korea
Detection rules
9
Indicators of compromise
15

Malware and tooling in Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

Malware and tooling: ARTEX, telegram, Claude Code

How Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool works

CrowdStrike reports an unattributed, likely Chinese-speaking, financially motivated actor using ARTEX, a recently released open-source agentic penetration testing tool developed in China, against multiple South Korean financial organizations from late September to early October 2026. Exposed open directories held Claude Code session histories, ARTEX configuration files and Claude memory files that reveal the LLM-assisted workflow.

CrowdStrike Intelligence assesses with moderate confidence that a likely Chinese-speaking, financially motivated actor, not attributed to any named adversary, used ARTEX (an open-source agentic penetration testing console developed in China) against multiple South Korean financial organizations between late September and early October 2026. CrowdStrike identified a bank's loan progress inquiry service (used by financial brokers) and another bank's employee mobile work-support system as targets; the total number of affected organizations is unconfirmed.

An exposed open directory on the actor's ARTEX host 38.244.50.120 (port 18899, path /.claude/CLAUDE.md) held Chinese-language pentesting prompts, ARTEX configuration files, Claude Code session histories and Claude memory files, and referenced Hong Kong-based attacker infrastructure, including a Hong Kong IP. The material shows an LLM-assisted workflow in which the operator also asked an LLM to identify Korean data sales channels and Telegram groups and how threat actors monetize stolen data. LLM backends observed were DeepSeek v4.1-flash (likely reached through the xcai.pro API proxy/reseller), GLM-5.3 and Grok 4.6, alongside Claude Code. Nine additional proxy IPs were used to obscure operations.

Korean press reporting corroborates the victimology. Shinhan Bank's 'M Shinhan' mobile portal for loan officers (about 25,000 customers affected, including 66 resident registration numbers and 97 CI values, names, phone numbers, annual income and loan limits) and KB Kookmin Bank's employee mobile work-support system (119 customers) reported incidents to the FSS on 30 September 2026. Reports also cite Hana Bank (89 customers) and BNK Financial (11 external staff) and say the same external hacking AI agent was suspected. Press analysts described the method as credential stuffing and AI-driven random value injection against non-core platforms, and a security expert reported ARTEX's 'autonomous penetration testing console' banner on compromised servers. The press-reported technical details are secondary sourcing and are not confirmed by CrowdStrike's report. No CVEs are cited.

CrowdStrike assesses that adversaries will likely continue to experiment with AI tooling to enhance operational tempo and capabilities.

MITRE ATT&CK techniques used in TL-2026-3008

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1090 Proxy

Credential Access

T1110.004 Credential Stuffing

Resource Development

T1583.003 Virtual Private Server; T1588.002 Tool; T1588.007 Artificial Intelligence

Reconnaissance

T1595.002 Vulnerability Scanning

Affected products and versions in Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

  • Shinhan Bank — M Shinhan mobile portal (loan officer / broker loan-status inquiry service)
    Vulnerable versions: Not applicable - service-level compromise
  • KB Kookmin Bank — Employee mobile work-support system
    Vulnerable versions: Not applicable - service-level compromise
  • Hana Bank — Business (sales) support system (press-reported)
    Vulnerable versions: Not applicable - service-level compromise

Remediation for Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

Immediate actions

  • Block and hunt for 38.244.50.120 and the nine published proxy IPs in firewall, proxy and web access logs
  • Hunt authentication logs of broker and employee mobile portals for credential-stuffing patterns (high-volume failed logins, many IDs per source IP)
  • Review non-core platforms (loan-broker portals, employee mobile work-support and sales-support systems) for exposed query endpoints and enumeration

Workarounds

  • Restrict broker and employee mobile portals to allow-listed networks or managed devices where feasible

Longer-term hardening

  • Require MFA beyond SMS or phone-number verification on broker and employee portals
  • Deploy rate limiting, bot management and anomaly detection on query and inquiry APIs
  • Treat agentic-AI-driven scanning as a baseline threat: monitor for high-tempo, automated parameter fuzzing

Weaknesses (CWE) in Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

CWE-307, CWE-521

Timeline of Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

  • Hankyung notes a prior Woori Bank breach in July 2026 as context for a run of Korean financial-sector incidents (month-level date; not attributed to this actor).
  • Abnormal access attempts detected at Shinhan Bank and KB Kookmin Bank (per Money Today).
  • Shinhan Bank and KB Kookmin Bank confirm information theft and report personal-data leak incidents to the Financial Supervisory Service.
  • Shinhan Bank incident (M Shinhan loan-officer portal, about 25,000 customers) reported by Hankyung; FSC/FSS convene an emergency meeting.
  • Press reports KB Kookmin (119 customers), Hana Bank (89) and BNK Financial (11 external staff) also hit, with the same external hacking AI agent suspected; ARTEX console observed on compromised servers.
  • Khan.co.kr publishes an article on the incidents, cited by CrowdStrike as an industry source.
  • CrowdStrike publishes its analysis of ARTEX use against South Korean financial organizations, with open-directory findings and IOCs.

Sources cited for Unattributed Actor Uses AI-Driven ARTEX Agentic Pentest Tool

Detection coverage for TL-2026-3008

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3008 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats