'ARTEX AI' Traces Surface in South Korean Bank Breaches: Emergency IOCs and API Defense Guide
Following the discovery of open-source LLM tool ARTEX in infrastructure targeting South Korean banks, security analysts published urgent WAF IOCs and API defens
Following the early October 2026 discovery of console identifiers for 'ARTEX'—an open-source LLM-based autonomous penetration testing tool—within web server infrastructure used in cyber intrusions against major South Korean financial institutions including Shinhan Bank and KB Kookmin Bank, cybersecurity researchers and defense teams on October 5 distributed candidate Indicators of Compromise (IOCs) for Web Application Firewalls (WAF) alongside urgent audit guidelines for exposed API authorization controls.

Image source: @ngnicky
The intrusions specifically compromised peripheral work-support portals, loan solicitor inquiry interfaces, and outsourced service portals rather than core transaction banking systems. While financial regulators and cyber investigators continue to determine whether ARTEX was leveraged across the entire intrusion lifecycle, the incident has highlighted how low-cost autonomous AI tools can accelerate brute-force harvesting, requiring defenses that look beyond simple IP and User-Agent blocking.
Attack Infrastructure Traces and CTI Analysis for 'ARTEX'
According to South Korean cybersecurity firms and Cyber Threat Intelligence (CTI) reports, the HTML title string ARTEX-自主渗透测试控制台 (ARTEX - Autonomous Penetration Testing Console) was identified on web servers used during the attacks.
ARTEX was originally released as an open-source security evaluation framework on GitHub after winning the 'Agent+' offensive capability challenge hosted by China's Baidu Security Response Center (BSRC) in August 2026.
- Multi-Agent Autonomous Pipeline: By connecting to commercial large language models, multiple specialized AI agents divide operational tasks—gathering initial system intelligence, mapping endpoint vulnerabilities, and formulating automated exploitation paths.
- Global CTI Footprint: Threat intelligence analysis by cybersecurity firm Oasis Security using its 'AGATHA' platform identified 359 unique IP addresses linked to ARTEX-associated activity across 14 countries and regions.
Security authorities emphasized that while ARTEX artifacts were detected on the attack infrastructure, attribution remains provisional. Adversaries frequently route attacks through spoofed IPs and compromised servers to disguise their operational origins, which forensic investigators are currently reviewing.
22-Second, $0.88 Automated Exploitation: Lab Verification and Direct API Vulnerabilities
AI security firm Everspin reproduced the ARTEX automated inquiry attack inside a testbed web environment mirroring South Korean financial institution architectures, illustrating the low economic barrier of AI-driven intrusion campaigns.
- Execution Speed: The automated pipeline identified endpoint weaknesses and completed target data retrieval across six rounds in just 22 seconds.
- Compute and Token Expenditure: The demonstration consumed approximately 44,000 tokens, with estimated costs based on leading frontier models (OpenAI ChatGPT and Anthropic Claude) amounting to roughly $0.88 (approximately 1,200 KRW).
- Recorded Data Exposure: Across seven affected financial firms, approximately 70,000 customer records were exposed, including 25,000 records at Shinhan Bank, 40,000 at Yegaram Savings Bank, and 2,200 at Welcome Savings Bank. In the Shinhan Bank breach, automated queries occurred at an average rate of one record every four seconds over a 30-hour window.
The underlying vulnerability that enabled such high speed and low cost was direct backend API invocation. Rather than driving automated browser sessions, the attack pipeline executed raw HTTP queries directly against unprotected lookup endpoints, substituting randomized application numbers across rotating international proxies. While payment credentials and transaction PINs were not exposed, the exfiltrated personal data—including customer names, mobile numbers, and annual incomes—presents serious secondary voice-phishing and targeted social-engineering risks.
Limitations of WAF Signatures and the 'Attack Cost Escalation' Strategy
Cybersecurity specialists caution that conventional pattern-matching and signature-based defenses cannot adequately stop AI-assisted automated harvesting.
Registering known ARTEX indicators—such as specific console paths, default User-Agent strings, and blacklisted IPs—provides essential initial containment. However, because attackers quickly route traffic through residential domestic proxies and mimic standard desktop Google Chrome browser signatures, static string matching is quickly bypassed.
Security architects advocate shifting toward an 'Attack Cost Escalation' defensive framework:
- Direct API Blocking and Client Attestation: Mandating cryptographic client integrity verification prevents headless scripts and AI agents from calling backend APIs directly. Forcing every request through an interactive browser context compels adversaries to run full browser instances and per-request AI reasoning, multiplying token consumption and execution latency until large-scale scanning becomes economically unviable.
- Comprehensive Authorization Review of Peripheral Systems: On October 4, South Korea's Financial Services Commission (FSC) convened an emergency meeting directing financial firms to block external access to non-essential systems. Institutions are instructed to audit loan broker portals, vendor workstations, and administrative consoles to eliminate unauthenticated lookup routes and broken object-level authorization flaws.
- Behavioral Rate Limiting and Anomaly Scoring: Implementing dynamic rate limiting based on continuous sequential query patterns and abnormal parameter substitution helps detect and throttle automated harvesting before bulk exfiltration occurs.
Sources
- Security Analyst @ngnicky on X: Financial Cyberattack IOC: ARTEX AI Indicators and Immediate Audit Items
- Electronic Times (ETNews): [Exclusive] Financial AI Hacking Achieved in 22 Seconds for Under $1
- The Hankyoreh IT/Economy: Circumstances Indicate AI 'ARTEX' Diverted into Hacking Weapon
- Financial Security Institute (FSI) Threat Intelligence Platform: FSI Comprehensive Incident Analysis and Intelligence Platform