started · updated
Shinhan Bank cyberattack linked to Chinese AI penetration tool
Security experts have identified traces of a Chinese-language, AI-based autonomous penetration testing tool in a web server suspected of being used in a cyberattack against Shinhan Bank. The tool, identified via Chinese strings in the HTML title of the server, is known as ‘ARTEX-自主渗透試控制台’, which translates to ‘AI Autonomous Penetration Test Console’.
Analysts suggest the attack utilized ‘credential stuffing’, a method where attackers use stolen ID and password combinations to gain unauthorized access. The suspected tool, ‘ARTEX AI’, is an open-source system based on Large Language Models (LLM) designed to automate processes such as information gathering, vulnerability scanning, and attack path planning. While developed for legitimate security testing, experts warn it can be repurposed to increase the efficiency of malicious cyberattacks.
Although the presence of these traces has raised suspicions of AI-driven automation in the breach, official confirmation regarding the specific use of ‘ARTEX AI’ in the Shinhan Bank incident has not yet been released by financial authorities or the bank. Shinhan Bank previously announced that the personal information of approximately 25,000 customers was leaked following an unauthorized bypass of identity verification procedures in its loan solicitor service.
Entities
ARTEX AI · Baidu · Genians · Shinhan Bank