# Solo Threat Actor Uses ARTEX Agentic AI Pentest Tool to Breach South Korean Financial Organizations and Steal Data

> A suspected lone, likely Chinese-speaking and financially motivated operator used the open-source, China-developed agentic penetration-testing tool ARTEX (DeepSeek v4.1-flash backend), plus Claude Code, GLM-5.3 and Grok 4.6 sessions, to breach weakly protected peripheral systems (loan-broker portals, employee work-support systems) at at least seven South Korean financial firms between 2026-09-27 and early October 2026. Roughly 68,000 customer and employee records were exposed; core internet and mobile banking were not compromised.

- **Published:** 2026-10-08T00:00:00Z
- **Last reviewed:** 2026-10-10T05:41:01.416Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3040
- **ID:** TL-2026-3040
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between roughly 27 September and early October 2026, a series of data breaches hit South Korean financial institutions. Korea's Financial Security Institute (KFSI) traced attack IPs and server logs from Shinhan Bank, the first institution to report, and found traces of ARTEX AI, an open-source LLM-based autonomous penetration-testing system distributed on GitHub and aimed at Chinese-speaking users. The string "ARTEX-自主渗透试控制台 (autonomous penetration test console)" appeared in the HTML titles of web servers used in the attacks. CrowdStrike (report published 2026-10-07) independently assessed the activity as the work of an unattributed, likely lone operator, Chinese-speaking and financially motivated with moderate confidence, based on the Chinese-developed tool and Chinese-language prompts. Korean officials stress that a human directed the tooling ("a hacker used the AI as a tool") and that AI involvement beyond what a skilled attacker with ordinary scanners could do is unproven.

The actor's infrastructure used a two-server layout: a Hong Kong-based main server (address not published) with open directories exposing Claude Code session histories, ARTEX configuration files and Claude memory files, and a separate ARTEX host at 38.244.50.120 (ARTEX console reachable on port 18899, with an exposed /.claude/CLAUDE.md holding a Chinese-language pentesting prompt). DeepSeek v4.1-flash was the primary LLM for the ARTEX instance, reportedly reached through the likely API proxy/reseller xcai.pro; other Claude Code sessions showed GLM-5.3 (Zhipu AI) and Grok 4.6 use. Nine proxy IPs were observed, and attack traffic came from IPs in eight countries including Korea, the United States, Japan and Hong Kong, with two to three IPs overlapping at each bank; when one was blocked the attacker switched to another. Authorities said the IPs alone cannot identify the operator, and the public availability of ARTEX means the tooling does not point to a specific actor.

Targets were internal, partner- and employee-facing systems rather than customer internet or mobile banking. At Shinhan Bank the actor bypassed identity checks on a loan-progress inquiry service used by financial brokers, entering random values to find valid customer numbers and then pulling related contact and financial records (about 25,700 people). At KB Kookmin Bank the actor reached an internal mobile work-support system (119 records); at Hana Bank an employee sales-support system (89 records). Other reported victims: BNK Busan Bank (11 contract workers), Yegaram Savings Bank (about 40,000), Welcome Savings Bank (over 2,200 corporate customer records) and Hyundai Capital, with two online lenders also reported; Woori Bank and NH NongHyup Bank were targeted but no damage was confirmed. The combined total is roughly 68,000 records and may change as banks re-audit. Stolen fields included names, phone numbers, resident registration numbers, annual income, credit limits and loan-application details. Regulators consider direct fund theft unlikely but warn of voice phishing and fraudulent texts. Exposed Claude sessions showed the actor asking where Korean breach data is typically sold and seeking Korean Telegram data-sale groups, which does not prove a sale occurred. Reported detection delays were more than 15 hours at Shinhan, nearly 42 hours at Hana and almost 68 hours at KB Kookmin. The initial-access method for Kookmin and the exfiltration channel were not described in the sources.

The Financial Services Commission ordered financial firms to shut off outside access to systems unless essential to the business, circulated the attacker IPs to about 500 financial firms, and called for a comprehensive audit of internal employee- and partner-facing systems; the National Police Agency Cyber Bureau is investigating and plans international cooperation. CrowdStrike expects adversaries to keep experimenting with AI tooling to raise operational tempo.

## MITRE ATT&CK

- T1583.003 Virtual Private Server
- T1588.007 Artificial Intelligence
- T1595.002 Vulnerability Scanning
- T1190 Exploit Public-Facing Application
- T1110 Brute Force
- T1119 Automated Collection
- T1090 Proxy
- T1588.002 Obtain Capabilities
- T1589 Gather Victim Identity Information
- T1213 Data from Information Repositories
- T1078 Valid Accounts
- T1567 Exfiltration Over Web Service

## Sources

- [Solo Hacker Used AI Tools to Breach South Korean Financial Organizations and Steal Data](https://cybersecuritynews.com/solo-hacker-used-ai-tools/)
- [CrowdStrike: Unknown Threat Actor Uses ARTEX to Target South Korean Finance](https://www.crowdstrike.com/en-us/blog/unknown-threat-actor-uses-artex-to-target-south-korean-finance/)
- [Kyunghyang Shinmun (Khan): ARTEX traces and victim list in South Korean bank breaches](https://www.khan.co.kr/en/article/202610042320007)
- [Korea JoongAng Daily: AI-driven hacks on banks leave customers fearing their data is fair game](https://www.koreajoongangdaily.com/korea/aidriven-hacks-on-banks-leave-customers-fearing-their-data-is-fair-game/12905416)
- [Herald Corp: Financial Security Institute traces attack IPs and logs at Shinhan Bank, confirming ARTEX use](https://biz.heraldcorp.com/article/10892497)
- [Korea AI hacks: Shinhan and seven lenders, 68,000 records](https://www.martincid.com/business/korea-ai-hacks-shinhan-seven-lenders-68000-records/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3040
