
In relation to the personal information leakage of about 25,000 Shinhan Bank customers, traces of 'ARTEX AI', a Chinese-based AI autonomous penetration testing console, were found on the suspected attack server, but it was not confirmed whether it was actually used, the security industry said.
AI-generated summary
Shinhan Bank announced on the 30th of last month that it had confirmed that the personal information of about 25,000 customers had been leaked by an external unauthorized person who ignored the identity verification process of the loan originator service.
‘AI Autonomous Penetration Test Console’ string on the suspected attack server
Circumstances related to open source ARTEX AI… Actual use is unconfirmed
(Seoul = Yonhap News) Reporter Kwon Ha-young = Circumstances showing the possibility that a tool that automatically performs the hacking process was used by an artificial intelligence (AI) agent was captured in an incident in which the personal information of approximately 25,000 Shinhan Bank customers was leaked.
On the server presumed to have been used in the attack, traces of a Chinese-based autonomous infiltration tool that uses AI to find vulnerabilities and plot attack routes on behalf of humans were discovered. It has not yet been confirmed whether this tool was used in the actual attack.
◇ ‘AI autonomous penetration testing console’ on the attack server… ARTEX AI related situation
According to the security industry on the 2nd, the string 'ARTEX-self-administered search engine' was confirmed in the HTML title of the web server used in the credential stuffing (random information substitution technique) attack believed to be targeting Shinhan Bank.
This is an expression meaning ‘AI autonomous penetration testing console,’ and can be interpreted as evidence showing the possibility that ‘ARTEX AI’ was operated in the relevant infrastructure or that a related environment was utilized.
Moon Jong-hyun, head of the Genius [263860] security center, made this diagnosis through his LinkedIn that day.
The HTML title is the page title displayed at the top of the web browser tab or window. Simply put, the phrase 'AI Autonomous Penetration Test Console' in Chinese is exposed as is in the title of the page of the web server used in the attack.
Credential stuffing is a hacking method in which an attacker brute-forces a combination of information, such as IDs and passwords, obtained in advance into multiple systems.
Typically, they illegally trade and collect ID and password data used for specific sites on information black markets such as the dark web, and then target users' practices of using the same ID and password on multiple sites.
In the past, attackers had to repeat these inputs manually, but recently, tools that automate this process with AI are increasingly being used.
ARTEX AI is a large-scale language model (LLM)-based autonomous penetration testing system released as open source on GitHub, focusing on Chinese.
It is designed to use LLM and a multi-agent structure to automate the process from information collection to vulnerability exploration, attack route planning, security tool execution, and vulnerability verification.
However, even technology developed for security checks can turn into a hacking tool if it falls into the hands of an attacker.
◇ Security AI becomes an automated hacking tool... It is unclear whether the attack will actually be used
Center Director Jonghyun Moon said, “Several threat analysts reasonably suspect that AI-based attack automation tools were used during this financial company attack.”
He pointed out, "On the surface, it is a tool developed to support security checks and penetration testing, but while it can be used as an efficient penetration testing tool in a permitted security verification environment, if abused by an attacker, it has the potential to be used as a means of increasing the automation and efficiency of actual cyber attacks."
As ARTEX AI is software (SW) released as open source, one of the concerns is that anyone can download and use it without separate approval.
One security expert mentioned this and said, "Although Chinese strings exist, the attacker's identity cannot be easily guessed as it is open source software that anyone can use. The biggest problem is that automation of attacks using open source software can become increasingly widespread."
ARTEX AI was introduced as the winning project in the 'Agent+' defense ability challenge led by China's Baidu BSRC this year.
However, it has not been confirmed through official agencies such as financial authorities or Shinhan Bank whether ARTEX AI was actually used in the attack during the Shinhan Bank hacking process.
Previously, Shinhan Bank announced on the 30th of last month that it had confirmed that the personal information of about 25,000 customers had been leaked by an external unauthorized person who bypassed the identity verification process of the loan originator service.
AI outlook — possibilities, not facts
Financial authorities will conduct an official investigation into the Shinhan Bank incident and check whether AI-based hacking tools were used.
Likely · Within weeks

KB Kookmin Bank announced that about 100 pieces of customer information were leaked due to an external intrusion through the mobile work support system for employees. This is the second commercial bank hacking incident following Shinhan Bank, and financial authorities are discussing response measures considering the possibility of further spread of damage.

As accidents caused by AI increase, there is a growing consensus that AI development companies should be held legally responsible, but it is pointed out that it is difficult to apply the existing legal system. The New York Times introduced related public opinion and legal academic opinions, and reported on cases where AI models such as Open AI and Antropic caused security incidents and the process of discussing responsibility.

Following Japan, Naver announced that it will strengthen overseas travel information search results in 45 major Asian regions, including Vietnam, Thailand, Indonesia, the Philippines, Taiwan, Hong Kong, and Macau, and provide weather, exchange rates, visas, entry guidance, safety notices, and AI-based popular restaurant and attraction recommendation services.

Boston Dynamics, an affiliate of Hyundai Motor Group, announced that it had equipped a humanoid robot Atlas with a next-generation robot hand with 13 degrees of freedom and demonstrated precision manipulation by applying tactile sensing technology. The new hand is the size of a human hand, has industrial durability, and is improving adaptability to real environments through a simtureal method.

In relation to the Shinhan Bank customer information leak incident, traces of 'ARTEX AI', a Chinese-based open source AI penetration testing tool, were confirmed on the server believed to have been used in the attack, but whether it was actually used for the attack has not been officially confirmed, a security expert said.

LG U+ announced that it will work with OptAI, a company specializing in AI model optimization, to develop token optimization technology that reduces GPU and power usage and increases processing efficiency. The two companies have secured technology to increase the amount of tokens that can be processed on the same GPU by up to four times the existing size by expanding the existing small language model lightweight technology to the server GPU environment, and jointly held a seminar on the 1st to discuss ways to apply the technology.