
In relation to the Shinhan Bank customer information leak incident, traces of 'ARTEX AI', a Chinese-based open source AI penetration testing tool, were confirmed on the server believed to have been used in the attack, but whether it was actually used for the attack has not been officially confirmed, a security expert said.
AI-generated summary
Shinhan Bank announced on the 30th of last month that it had confirmed that the personal information of about 25,000 customers had been leaked by an external unauthorized person who ignored the identity verification process of the loan originator service.
Unconfirmed whether the attack is actually used... Expert "suspects automation of AI-based attacks
(Seoul = Yonhap News) Reporter Kwon Ha-young = Traces of a Chinese-based open source artificial intelligence (AI) penetration testing tool were found on a server believed to have been used in a cyber attack in connection with the Shinhan Bank customer information leak incident.
According to the security industry on the 2nd, the string 'ARTEX-self-administered search engine' was confirmed in the HTML title of the web server used in the credential stuffing (random information substitution technique) attack believed to be targeting Shinhan Bank.
This is an expression meaning ‘AI autonomous penetration testing console,’ and can be interpreted as evidence showing the possibility that ‘ARTEX AI’ was operated in the relevant infrastructure or that a related environment was utilized.
Moon Jong-hyun, head of the Genius [263860] security center, made this diagnosis through his LinkedIn that day.
ARTEX AI is a large-scale language model (LLM)-based autonomous penetration testing system released as open source on GitHub, focusing on Chinese.
It is designed to use LLM and a multi-agent structure to automate the process from information collection to vulnerability exploration, attack route planning, security tool execution, and vulnerability verification.
Center Director Jonghyun Moon said, “Several threat analysts reasonably suspect that AI-based attack automation tools were used during this financial company attack.”
He pointed out, "On the surface, it is a tool developed to support security checks and penetration testing, but while it can be used as an efficient penetration testing tool in a permitted security verification environment, if abused by an attacker, it has the potential to be used as a means of increasing the automation and efficiency of actual cyber attacks."
ARTEX AI was introduced as the winning project in the 'Agent+' defense ability challenge led by China's Baidu BSRC this year.
However, it has not been confirmed through official agencies such as financial authorities or Shinhan Bank whether ARTEX AI was actually used in the attack during the Shinhan Bank hacking process.
Previously, Shinhan Bank announced on the 30th of last month that it had confirmed that the personal information of about 25,000 customers had been leaked by an external unauthorized person who bypassed the identity verification process of the loan originator service.
AI outlook — possibilities, not facts
Financial authorities plan to strengthen cybersecurity inspections in the financial sector following the Shinhan Bank accident
Likely · Within weeks

Following Japan, Naver announced that it will strengthen overseas travel information search results in 45 major Asian regions, including Vietnam, Thailand, Indonesia, the Philippines, Taiwan, Hong Kong, and Macau, and provide weather, exchange rates, visas, entry guidance, safety notices, and AI-based popular restaurant and attraction recommendation services.

Boston Dynamics, an affiliate of Hyundai Motor Group, announced that it had equipped a humanoid robot Atlas with a next-generation robot hand with 13 degrees of freedom and demonstrated precision manipulation by applying tactile sensing technology. The new hand is the size of a human hand, has industrial durability, and is improving adaptability to real environments through a simtureal method.

LG U+ announced that it will work with OptAI, a company specializing in AI model optimization, to develop token optimization technology that reduces GPU and power usage and increases processing efficiency. The two companies have secured technology to increase the amount of tokens that can be processed on the same GPU by up to four times the existing size by expanding the existing small language model lightweight technology to the server GPU environment, and jointly held a seminar on the 1st to discuss ways to apply the technology.

42Dot, the global software center of Hyundai Motor Group, announced that it will seek to strengthen the competitiveness of software-centered automobile technology by securing three key talents from global IT companies, including recruiting Angelo Corsaro, founder of the open source communication protocol 'Xeno', as a senior researcher.

An investigation by American cybersecurity company Proofpoint revealed that TA419, a hacking group linked to the Chinese government, carried out phishing attacks by impersonating AI policy officials and corporate executives in the United States. Hackers attempted to steal cloud accounts by impersonating Lynn Parker, former senior deputy director of the White House Office of Science and Technology Policy, and high-ranking Antropic executives, and targeted AI experts at think tanks, universities, and law firms in the United States. It is analyzed that this attack was aimed at identifying trends in US AI policy amidst the US-China AI strategy competition.

China's Huawei unveiled its new smartphone 'Mate 90' series equipped with a 'Tau law'-based chip designed in-house to respond to the US semiconductor regulations on China. This new product is expected to serve as a test bed to measure Huawei's cutting-edge technology and market viability amid U.S. regulations.