Hackers Used a Chinese AI Tool to Breach South Korean Banks, Here's How It Worked
The Breach That Started With a Login Screen
The login screen is not supposed to be the weak point.
Shinhan Bank learned otherwise. On September 30, the bank disclosed that an unauthorized outsider bypassed identity verification procedures in its loan broker service. The intruder walked out with the personal information of approximately 25,000 customers. Names. Phone numbers. Annual income. Calculated borrowing limits. The kind of data that makes a phishing email feel real. The kind of data that turns a stranger into someone who knows exactly what to say.
The breach did not stay contained. Within days, six other South Korean financial firms reported similar intrusions. KB Kookmin Bank. Hana Bank. BNK Busan Bank. Woori Bank. NH NongHyup Bank. Yegaram Savings Bank. Some lost customer records. Some blocked the attempt before data left the building. All of them found the same thing when investigators traced the traffic back: a single IP address connecting the attacks.
One attacker. Multiple banks. The same weekend. That pattern does not happen by accident. It happens when someone has a tool that scales.
Security researchers found traces of that tool on the servers. The HTML title of an attacking web server read "ARTEX, 自主渗透测试控制台." The phrase translates to "autonomous penetration testing console." The string of characters sat there in plain sight, a calling card left by software that was never supposed to leave a trace.
The tool had a name. The tool had a purpose. The purpose was not what its creators intended.
What Is ARTEX AI and Why It Matters
ARTEX AI is not a virus. It is not malware. It is not a script that someone downloaded from a shady forum and ran with a single command. ARTEX AI is a large language model-based autonomous penetration testing system. It was released as open source on GitHub. The documentation and user interface are primarily in Chinese.
In its intended form, ARTEX AI helps security professionals find weaknesses in their own systems before attackers do. It combines large language models with a multi-agent architecture. One agent gathers information about a target. Another scans for vulnerabilities. A third plans the attack path. A fourth executes security tools and verifies whether the vulnerability actually works. The system automates the entire penetration testing workflow. Human testers used to spend days on reconnaissance and manual probing. ARTEX AI compresses that timeline into hours. Sometimes minutes.
The project won the "Agent+" offensive and defensive capability challenge led by Baidu's Security Response Center this year. It was celebrated as an achievement. A tool that could make cybersecurity cheaper, faster, and more accessible.
Then someone pointed it at a bank.
The distinction between a penetration testing tool and an attack tool is not technical. It is legal and ethical. The same software that helps a security team patch a hole can help a criminal climb through it. Moon Jong-hyun, head of the Genians Security Center, said the quiet part out loud: "In authorized security verification environments, it can be used as an efficient penetration testing tool, but if attackers abuse it, there is a possibility it could be repurposed as a means of increasing the automation and efficiency of actual cyberattacks."
The tool does not care who runs it. The tool does not know the difference between a red team and a bank robbery. The tool does what it is told.
The Attack Chain, From Scan to Shell
The entry point was not a bank vault. It was a side door.
South Korean banks protect their core systems with layers of encryption, multi-factor authentication, and continuous monitoring. Breaking into the core would require resources and patience that most attackers do not have. So the attacker ignored the core. The attacker targeted the noncore systems instead. Sales support platforms. Loan broker services. The systems that connect banks to partners, contractors, and third-party vendors. The systems that exist because business needs them, not because security teams designed them first.
The attack method was credential stuffing. This is not a sophisticated technique in the traditional sense. The attacker takes a list of usernames and passwords stolen from previous breaches and tries them against a target system. People reuse passwords. They always have. A password leaked from a fitness app in 2023 might still open a loan officer's account in 2026.
What changed is the speed and scale. A human attacker typing credentials into a login form can test a few hundred combinations per hour. An AI-powered tool can test thousands. ARTEX AI does not just guess. It analyzes the results. It learns which combinations work. It adjusts the attack path based on what it finds. The tool does not sleep. It does not get tired. It does not stop when the first login fails.
The attacker did not need zero-day exploits. The attacker did not need insider access. The attacker needed a list of leaked credentials and a tool that could use them faster than any human. That was enough to walk through the front door of seven financial institutions.
Seven Banks, One IP Address
The scope of the campaign became clear as the week unfolded.
Shinhan Bank reported the largest breach: approximately 25,000 customers affected. Yegaram Savings Bank reported 40,000 cases. KB Kookmin Bank reported 153 individuals. Hana Bank reported 89. BNK Busan Bank reported 11 outsourced workers whose names, phone numbers, birth dates, and email addresses were briefly visible on a page that should have been locked.
Woori Bank and NH NongHyup Bank detected the intrusion attempts and blocked them. No data left. That fact matters. It suggests the tool is effective but not unstoppable. Detection still works. Response still works. But the margin for error has shrunk.
The common thread was the IP address. Authorities found the same attacker's IP address across all seven affected firms. That detail rules out coincidence. It points to a single operator or a small group running a coordinated campaign. It also points to a tool that could be aimed at multiple targets without rebuilding the attack from scratch each time.
The Financial Services Commission convened an emergency meeting. Chair Lee Eok-won told the room what everyone already suspected: "We cannot rule out the possibility of attacks using AI." He ordered firms to block external access to systems unless essential for business operations. The order was practical. It was also a concession that the usual defenses were not enough.
The AI Attack Tool Ecosystem
ARTEX AI did not appear alone.
Analysts at AhnLab's Security Intelligence Center found approximately 600 additional IP addresses hosting ARTEX instances worldwide. They traced the infrastructure from known servers to related ones. The tool is not a single installation on a single machine. It is an open-source project that anyone can deploy. The 600 IP addresses include servers run by security researchers, red teams, and penetration testers doing legitimate work. They also include servers run by people whose intentions are harder to classify.
Some of the same servers ran another AI-based attack platform called CyberStrikeAI. The presence of multiple tools on the same infrastructure suggests an ecosystem. A market. A supply chain for automated attacks that did not exist five years ago.
ARTEX AI is not even the cheapest option. A report from Gambit Security documented a campaign that stole over 500,000 credit cards using three open-source AI tools. The average cost per attack was $25. The cheapest attack cost just over $3. The most expensive cost $79. The hackers used simple prompts. One of them read: "Identify vulnerabilities in the system and break in."
Bill Gates saw this coming. In an interview, he said the main risk of AI is not that it becomes rogue. The main risk is that ill-intentioned people use it to do things that used to cost millions of dollars. "There has never been a weapon as powerful as the combination of people with ill intentions using the latest AI tools," he said.
Gates was not describing a future scenario. He was describing the present.
The South Korean Response
President Lee Jae Myung called for a thorough investigation. His spokesperson said the president instructed authorities to "take the matter seriously, conduct a thorough investigation and spare no effort in coming up with measures to address the issue." The language was formal. The urgency was real.
The Financial Services Commission ordered financial institutions to block external access unless essential for business operations. The order will disrupt workflows. Loan broker services will slow down. Third-party integrations will break. That is the point. The commission decided that convenience was less important than containment.
The response raised an uncomfortable question. Shinhan Bank, the institution with the largest breach, had the lowest information security budget among South Korea's top four commercial banks. 40.59 billion won this year. Approximately $30.2 million. KB Kookmin Bank spent more than double that amount: 86.07 billion won. Hana Bank spent 63.63 billion won. Woori Bank spent 61.56 billion won.
The numbers do not prove causation. A larger security budget does not guarantee immunity. A smaller budget does not guarantee breach. But the pattern invites scrutiny. Banks report record profits. Cybersecurity spending varies. When the breach happens, the customers pay the price in exposed data and the bank pays the price in reputation. The equation does not balance.
What This Means for Your Bank
The attack succeeded because of a gap that most banks know about and most customers never think about. Core systems get the attention. Noncore systems get the leftovers. The loan broker platform. The sales support tool. The vendor portal that someone set up in 2019 and nobody has audited since. These systems hold real data. They connect to real networks. They sit outside the moat that protects the vault.
AI makes the gap wider. Credential stuffing used to be a numbers game. The attacker needed enough leaked credentials and enough time to test them. AI changes the math. It automates the testing. It learns from failures. It adapts. A tool like ARTEX AI can probe dozens of noncore systems in the time it takes a human to probe one.
The breach at Shinhan Bank exposed names, phone numbers, income data, and borrowing limits. That information does not let a criminal drain an account. It lets a criminal make a phone call that sounds convincing. The Financial Services Commission warned that the exposed data could facilitate voice phishing and fraudulent text messages. The breach is not the end of the harm. The breach is the beginning.
Customers can change passwords. They can enable multi-factor authentication where available. They can treat unexpected calls from their bank with suspicion. These steps help. They do not solve the underlying problem. The problem belongs to the institutions that hold the data.
The Quiet Shift Nobody Wants to Name
For years, the cybersecurity industry used a comfortable phrase: "sophisticated attacker." It implied resources. It implied patience. It implied a level of skill that most criminals did not possess. The phrase served a purpose. It reassured people that the biggest threats came from nation-states and organized crime syndicates. It suggested that ordinary hackers could not do that much damage.
ARTEX AI makes the phrase obsolete.
A tool that costs nothing to download, runs on commodity hardware, and automates the entire penetration testing workflow does not require sophistication. It requires a target. It requires a reason. It requires a willingness to press enter. The barrier to entry has collapsed. The skills gap that used to protect institutions from low-level attackers has narrowed to nothing.
The attackers who hit South Korean banks did not need to understand how credential stuffing works. They did not need to know how to write a script or configure a proxy chain. They needed to point the tool at a target and wait. The tool did the rest.
Security teams now face a different problem. The threat is not a person. The threat is a process. A process that runs twenty-four hours a day, learns from every attempt, and never gets bored. You cannot outwork it. You can only outdesign it. Better segmentation. Better monitoring. Better assumptions about which systems are actually exposed.
The quiet shift is this: the question is no longer whether your defenses are strong enough to stop a determined human. The question is whether they are strong enough to slow down a machine that does not get tired.
Comments
Post a Comment