Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Chinese AI Agent Pulled From Public View After Breaching South Korean Banks

Дата публикации: 09-10-2026 10:12:14

A Chinese-developed open-source AI penetration testing tool called ARTEX was used to steal personal data from 68,000 customers at multiple South Korean banks. The developer has now taken the project closed source after the breaches came to light. The case highlights how accessible AI agents lower the bar for sophisticated financial cyberattacks.

Основное содержимое страницы с новостью.

A single operator, likely sitting somewhere in southern China, spent weeks last month quietly testing the limits of what one person armed with off-the-shelf artificial intelligence could achieve against some of South Korea’s largest financial institutions. The tool at the center of those attacks now sits behind closed doors.

The developer who built ARTEX, an open-source system designed to automate penetration testing, moved the project to closed source Thursday. “Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source,” the individual posting under the GitHub handle Autumn-27 wrote. “No further versions will be released to the public nor will maintenance support be provided.” The project’s GitHub page has since disappeared. Reuters first reported the decision.

But the damage was already done. South Korean authorities say the breaches exposed personal information belonging to roughly 68,000 people. Data taken included names, contact details, annual income figures and personal-loan limits. Such details hold real value on underground markets. Scammers and identity thieves pay for them.

The attacks began in late September and continued into early October. They struck at least seven financial firms, including major banks such as Shinhan, KB Kookmin and Hana. Investigators noticed something unusual right away. The intrusions carried signatures of ARTEX. The Wall Street Journal broke the story of the tool’s involvement on October 6.

ARTEX itself does not contain a large language model. It acts as an orchestration layer. Users connect it to models from Anthropic, OpenAI, DeepSeek or others. The system then deploys those models like members of a coordinated team. One agent plans the attack path. Others execute scans, write code or interpret results. The original purpose was defensive. Organizations could use it to find weaknesses in their own networks before adversaries did. Li Puhua, the Chinese cybersecurity engineer known as Autumn who created the tool, made that clear in its documentation.

Yet the code was freely available. Anyone could download it, modify it and point it at any target. That openness proved its undoing. The Korea Financial Security Institute traced attack IP addresses and server logs from Shinhan Bank, the first institution to report a breach, and confirmed the presence of ARTEX. The Herald Business reported those findings on October 3.

CrowdStrike went further. The American cybersecurity firm examined exposed directories on the attacker’s infrastructure. They found Claude Code session histories, ARTEX configuration files and memory records that documented the entire operation. The primary model used was DeepSeek v4.1-flash. Supplementary sessions pulled in GLM-5.3 and Grok 4.6. One Hong Kong server served as the main command post. Another hosted the ARTEX instance aimed at Korean targets.

The logs revealed more than technical details. At one point the operator asked Claude where threat actors typically sell stolen Korean data and requested help locating Telegram groups that traded such information. In another session, the same user asked the model to generate a security researcher resume that listed a 26-year-old living in Maoming, a city in Guangdong province. CrowdStrike assessed with moderate confidence that the threat actor is a Chinese speaker motivated by financial gain rather than state direction. The firm stopped short of naming an individual.

South Korean police opened a formal investigation. The National Police Agency’s cyber terror unit took the lead. Officials noted the attacks routed through more than 20 IP addresses across a dozen countries, including the United States, Japan and Germany. This routing complicated attribution. At Shinhan Bank, the intruder accessed a loan-progress inquiry service used by financial brokers and exposed records for more than 25,000 customers. Other breaches hit employee mobile work-support systems and partner-facing portals. Core customer banking platforms stayed untouched. The attackers focused on softer, internal-facing targets.

The incidents sent ripples through Seoul’s financial sector. Banks rushed to notify customers. Regulators called for audits of employee-facing systems. President Lee Jae-myung urged stronger defenses. Shares in some local cybersecurity companies rose on expectations of higher spending.

ARTEX had drawn attention even before the attacks. In September it won first place in Baidu’s Agent+ competition, a Chinese contest focused on AI systems for both attack and defense scenarios. That victory signaled the tool’s sophistication. Yet its public release on GitHub in July made it available to anyone with basic technical skills. The developer added warnings against unauthorized use only after early reports of the bank breaches surfaced.

Now the project is effectively dead in its original form. The developer distanced himself from illegal activity. “The original aim of ARTEX was to help enterprises and organizations conduct security risk testing and improve their security capabilities,” Autumn-27 wrote. The statement opposed any illegal use and disclaimed responsibility for violations of law. No direct mention of the Korean banks appeared.

Security researchers see this episode as an early warning. One person, aided by readily available AI agents, conducted a campaign that once required teams of specialists and months of preparation. The barrier to entry for sophisticated intrusions has dropped. Models that can reason through complex tasks, generate working exploit code and adapt on the fly change the math for both attackers and defenders.

And the tool’s withdrawal raises its own questions. Closing the source may slow casual copycats. It does nothing to stop those who already downloaded copies or forked the repository before the takedown. Similar frameworks will almost certainly appear under different names. The knowledge exists. The models remain accessible through commercial APIs.

Financial institutions worldwide are watching closely. South Korea’s experience shows how quickly AI-augmented attacks can scale across multiple organizations. The data stolen here carries long-term risk. Income details and loan limits help criminals craft convincing phishing campaigns or impersonation scams. Once information reaches underground forums, it circulates indefinitely.

CrowdStrike’s analysis, released this week, paints a picture of an operator who treated AI as a force multiplier. The attacker did not simply feed prompts into a chatbot. The person built a workflow that combined planning agents, execution agents and multiple language models into something that operated with limited human oversight. That model of operation can target many victims in parallel. It reduces the need for deep personal expertise in every phase of an attack.

Yet human judgment still mattered. The operator reviewed outputs, selected targets and decided when to pull data. AI accelerated the process. It did not replace the person directing it. This distinction matters for those building detection systems. Signatures based solely on known malware will miss these campaigns. Behavioral analysis, anomaly detection in API calls to large language models and tighter controls on internal systems become more important.

South Korean officials have not ruled out international cooperation in the investigation. China has not commented publicly on the matter. Anthropic, whose Claude product appeared in the attacker’s sessions, did not respond to requests for comment at the time of CrowdStrike’s report.

The ARTEX affair arrives at a moment when banks and regulators already worry about AI’s dual-use nature. Tools that help red teams find flaws can, in the wrong hands, become precision weapons. Open-source development speeds innovation but also spreads capability faster than control mechanisms can adapt. The decision to close ARTEX represents one developer’s attempt to hit pause. Whether the broader industry can find workable guardrails remains an open and urgent question.

More attacks of this style seem likely. The code, the models and the motivation all exist in abundance. What happened in Seoul this fall may soon look like the opening chapter rather than an isolated incident.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1AI Tools and Sloppy Opsec Expose Suspected Chinese Hacker Behind South Korean Bank Breaches08.3309-10-2026
2Chinese developer makes ARTEX AI agent closed-source after Korean bank hack 09.0709-10-2026
3Un agent IA offensif industrialise les compromissions : autopsie des attaques ARTEX08.6508-10-2026
4South Korea’s Banks Under AI-Assisted Assault: President Lee Demands Answers015.8508-10-2026
5Китайский хакер взломал банки Южной Кореи с помощью искусственного интеллекта07.9808-10-2026
6CrowdStrike Says South Korean Bank Hack Suspect May Be a 26-Year-Old Using ARTEX and Claude Code08.7308-10-2026
7Кибератака с ИИ: китайскоязычный хакер взломал системы банков Южной Кореи07.9508-10-2026
8South Korea warns of possible AI use in banking hacks07.5406-10-2026
9Хакеры атаковали банки Южной Кореи, утекли данные десятков тысяч клиентов07.0402-10-2026
10When AI Agents Turn on Their Masters: Hackers Lose Email Harvest to Rogue Security Tools08.3502-10-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 11.64. Источник: www.webpronews.com.