Threat reportData BreachTL-2026-3040

Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to Breach South Korean Financial Organizations and Steal Data

highACTIVE

Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to (TL-2026-3040), also tracked as ARTEX-enabled South Korean financial campaign, is a high-severity data breach, first published 2026-10-08 and last reviewed 2026-10-10. It has no confirmed attribution, affects Shinhan Bank Loan-progress inquiry service for financial brokers, maps to 12 MITRE ATT&CK techniques (T1078, T1090, T1110), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-3040

Threat ID
TL-2026-3040
Also known as
ARTEX-enabled South Korean financial campaign
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
finance, banking, lending, savings-banks
Target regions
south korea
Detection rules
9
Indicators of compromise
28
Updates
2026-10-10 · 3 updates · revalidated 3× · latest source

Malware and tooling in Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

Malware and tooling: ARTEX, Claude Code, DeepSeek v4.1-flash, GLM-5.3, Grok 4.6

How Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to works

A suspected lone, likely Chinese-speaking and financially motivated operator used the open-source, China-developed agentic penetration-testing tool ARTEX (DeepSeek v4.1-flash backend), plus Claude Code, GLM-5.3 and Grok 4.6 sessions, to breach weakly protected peripheral systems (loan-broker portals, employee work-support systems) at at least seven South Korean financial firms between 2026-09-27 and early October 2026. Roughly 68,000 customer and employee records were exposed; core internet and mobile banking were not compromised.

Between roughly 27 September and early October 2026, a series of data breaches hit South Korean financial institutions. Korea's Financial Security Institute (KFSI) traced attack IPs and server logs from Shinhan Bank, the first institution to report, and found traces of ARTEX AI, an open-source LLM-based autonomous penetration-testing system distributed on GitHub and aimed at Chinese-speaking users. The string "ARTEX-自主渗透试控制台 (autonomous penetration test console)" appeared in the HTML titles of web servers used in the attacks. CrowdStrike (report published 2026-10-07) independently assessed the activity as the work of an unattributed, likely lone operator, Chinese-speaking and financially motivated with moderate confidence, based on the Chinese-developed tool and Chinese-language prompts. Korean officials stress that a human directed the tooling ("a hacker used the AI as a tool") and that AI involvement beyond what a skilled attacker with ordinary scanners could do is unproven.

The actor's infrastructure used a two-server layout: a Hong Kong-based main server (address not published) with open directories exposing Claude Code session histories, ARTEX configuration files and Claude memory files, and a separate ARTEX host at 38.244.50.120 (ARTEX console reachable on port 18899, with an exposed /.claude/CLAUDE.md holding a Chinese-language pentesting prompt). DeepSeek v4.1-flash was the primary LLM for the ARTEX instance, reportedly reached through the likely API proxy/reseller xcai.pro; other Claude Code sessions showed GLM-5.3 (Zhipu AI) and Grok 4.6 use. Nine proxy IPs were observed, and attack traffic came from IPs in eight countries including Korea, the United States, Japan and Hong Kong, with two to three IPs overlapping at each bank; when one was blocked the attacker switched to another. Authorities said the IPs alone cannot identify the operator, and the public availability of ARTEX means the tooling does not point to a specific actor.

Targets were internal, partner- and employee-facing systems rather than customer internet or mobile banking. At Shinhan Bank the actor bypassed identity checks on a loan-progress inquiry service used by financial brokers, entering random values to find valid customer numbers and then pulling related contact and financial records (about 25,700 people). At KB Kookmin Bank the actor reached an internal mobile work-support system (119 records); at Hana Bank an employee sales-support system (89 records). Other reported victims: BNK Busan Bank (11 contract workers), Yegaram Savings Bank (about 40,000), Welcome Savings Bank (over 2,200 corporate customer records) and Hyundai Capital, with two online lenders also reported; Woori Bank and NH NongHyup Bank were targeted but no damage was confirmed. The combined total is roughly 68,000 records and may change as banks re-audit. Stolen fields included names, phone numbers, resident registration numbers, annual income, credit limits and loan-application details. Regulators consider direct fund theft unlikely but warn of voice phishing and fraudulent texts. Exposed Claude sessions showed the actor asking where Korean breach data is typically sold and seeking Korean Telegram data-sale groups, which does not prove a sale occurred. Reported detection delays were more than 15 hours at Shinhan, nearly 42 hours at Hana and almost 68 hours at KB Kookmin. The initial-access method for Kookmin and the exfiltration channel were not described in the sources.

The Financial Services Commission ordered financial firms to shut off outside access to systems unless essential to the business, circulated the attacker IPs to about 500 financial firms, and called for a comprehensive audit of internal employee- and partner-facing systems; the National Police Agency Cyber Bureau is investigating and plans international cooperation. CrowdStrike expects adversaries to keep experimenting with AI tooling to raise operational tempo.

MITRE ATT&CK techniques used in TL-2026-3040

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Command and Control

T1090 Proxy

Credential Access

T1110 Brute Force

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.003 Virtual Private Server; T1588.002 Obtain Capabilities; T1588.007 Artificial Intelligence

Reconnaissance

T1589 Gather Victim Identity Information; T1595.002 Vulnerability Scanning

Affected products and versions in Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

  • Shinhan Bank — Loan-progress inquiry service for financial brokers
    Vulnerable versions: identity-check bypass; about 25,700 customers exposed
  • KB Kookmin Bank — Internal mobile work-support system
    Vulnerable versions: 119 records exposed
  • Hana Bank — Employee sales-support system (ODS)
    Vulnerable versions: 89 records exposed
  • Yegaram Savings Bank — Customer data systems
    Vulnerable versions: about 40,000 customers reported

Remediation for Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

Immediate actions

  • Block and hunt for the published actor and proxy IPs and xcai.pro in perimeter, proxy, WAF and application logs
  • Cut off external access to broker, partner, employee and outsourced-developer systems unless essential to the business
  • Rate-limit and alert on automated sequential or random lookups of customer numbers in loan-inquiry and similar services
  • Enforce strong authentication on broker portals and employee work-support systems; rotate credentials reused from earlier breaches

Workarounds

  • Evaluate requests by how they arrive (request patterns) rather than only by who is connecting
  • Prepare customer communications and monitoring for voice-phishing and fraudulent-text follow-on abuse of leaked data

Longer-term hardening

  • Include broker portals, employee systems, support services, APIs and other connected applications in security reviews, not only core banking
  • Segment sensitive systems from peripheral partner- and employee-facing applications
  • Monitor for unusual bulk or enumerating lookups of customer records and shorten detection time (reported 15 to 68 hours)
  • Use AI-assisted testing internally to find weaknesses before attackers do

Weaknesses (CWE) in Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

CWE-639

Timeline of Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

  • ARTEX open-source agentic penetration-testing tool released on GitHub (developer GitHub ID reported as Autumn-27)
  • ARTEX reportedly took first place among about 150 teams in a Baidu-hosted cyber offense-defense competition
  • Latest ARTEX version released, days before the intrusions began
  • Attack on KB Kookmin Bank began; intrusions at the affected financial firms continued through about 2026-09-30
  • First breach surfaced publicly at Shinhan Bank (loan-broker inquiry service, about 25,700 customers)
  • Genians Security Center publicized ARTEX evidence found on servers used in the attacks
  • Korea Financial Security Institute confirmed ARTEX use after tracing attack IPs and server logs from Shinhan Bank; attacker IPs shared with police
  • Financial Services Commission held an emergency meeting; the President ordered a thorough investigation
  • Seven financial firms reported breaches (about 68,000 records combined); regulators told firms to cut off non-essential outside access and shared attacker IPs with about 500 firms
  • Yonhap reports AhnLab found ARTEX instances on about 600 IPs worldwide (some also running CyberStrikeAI) and cautions that ARTEX presence does not prove involvement in the intrusions; police examine ARTEX-linked traces.
  • South Korea's Financial Services Commission issued a consumer alert on phishing and loan scams following the breaches.
  • CrowdStrike published its assessment of an unattributed, likely Chinese-speaking, financially motivated actor using ARTEX, with IOCs
  • ARTEX developer converted the project to closed source and discontinued updates and support after the abuse became public.
  • Deadline for lenders to report results of the emergency security inspection; Cyber Security News coverage published

Update history for TL-2026-3040

Sources cited for Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to

Detection coverage for TL-2026-3040

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3040 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats