
Signs of a Chinese-language autonomous artificial intelligence penetration testing tool have been detected on a server believed to have been used in the attack that led to the leak of Shinhan Bank customer data. It has not been confirmed whether AI was actually used in the hacking, but the security industry is focusing on the possibility that generative AI could serve as a tool that automates everything from scanning for vulnerabilities to designing attack paths.
According to the security industry on the 2nd, the string "ARTEX — 自主渗透测试控制台" was found in the HTML title of some web servers believed to have been used in credential stuffing attacks, in which login information is entered at random, and in attacks exploiting application programming interface (API) vulnerabilities targeting multiple sites in South Korea recently. The phrase means "autonomous penetration testing console," an indication that "ARTEX AI" may have been operated on that infrastructure or that a related environment was used.
Moon Jong-hyun, head of the Genians (263860) Security Center, released the analysis on his LinkedIn account the same day, saying, "Multiple threat analysts reasonably suspect that AI-based attack automation tools may have been used in the course of this attack."
ARTEX AI is a large language model (LLM)-based autonomous penetration testing system released as open source on GitHub, primarily in Chinese. It combines LLM and multi-agent technology and is designed to automatically carry out the penetration testing process, including gathering information on targets, scanning for vulnerabilities, planning attack paths, running security tools and verifying vulnerabilities.
What sets it apart is that AI agents can continuously handle tasks that people previously performed individually, such as identifying targets, analyzing vulnerabilities, mapping out attack paths and running tools. ARTEX AI was also introduced as the winning project at the "Agent+" offensive and defensive capability challenge led by China's Baidu Security Response Center (BSRC) this year.
Moon said, "In authorized security verification environments, it can be used as an efficient penetration testing tool, but if attackers abuse it, there is a possibility it could be repurposed as a means of increasing the automation and efficiency of actual cyberattacks."
Shinhan Bank said on the 30th of last month that it had confirmed the personal information of about 25,000 customers was leaked after an unauthorized outsider bypassed identity verification procedures in its loan broker service.
However, it has not been confirmed so far whether ARTEX AI was used as an actual attack tool in the leak of Shinhan Bank customer data.






