{"slug": "ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches", "title": "AhnLab finds ARTEX on 600 IPs as police probe South Korean bank breaches", "summary": "South Korea's National Police Agency is investigating ARTEX traces on IP addresses tied to attacks on seven financial firms, while AhnLab's Security Intelligence Center separately found about 600 IP addresses worldwide hosting ARTEX instances, according to Yonhap's October 6th report. The breaches at Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital exposed data tied to about 68,000 people, though investigators have not established that ARTEX was used in the intrusions. ARTEX, tied to the GitHub account Autumn-27, is described in its repository README as a Go backend with a Next.js interface and a multi-agent architecture that coordinates agents across reconnaissance, vulnerability checks and attack-path planning using external language-model providers including Anthropic or OpenAI.", "body_md": "# AhnLab finds ARTEX on 600 IPs as police probe South Korean bank breaches\n\n**Yonhap reported on October 6th that AhnLab identified ARTEX instances on about 600 IP addresses worldwide. Police are separately investigating traces linked to attacks on seven financial firms, where data tied to about 68,000 people was exposed.**\n\n        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)\n        · Published \n\nPrimary source: [The Wall Street Journal](https://www.wsj.com/world/asia/hackers-use-chinese-ai-tool-to-hit-south-korean-banks-exposing-new-risk-5d4d3885?mod=rss_Technology)\n\n## Why it matters\n\nThe breaches affected seven financial firms, and investigators have not established whether ARTEX was used. A trace on an attack server does not show that an AI agent conducted the intrusion. The exposed customer data and suspected routes through less-protected systems remain immediate risks.\n\nSouth Korea's National Police Agency is investigating ARTEX traces on IP addresses associated with attacks against financial firms. Separately, AhnLab's Security Intelligence Center found about 600 IP addresses worldwide hosting [ARTEX instances](https://github.com/Autumn-27/ARTEX?ref=runtimewire), according to [Yonhap's October 6th report](https://www.yna.co.kr/amp/view/AKR20261006118100017?ref=runtimewire). The global count describes observed hosting; it does not establish that each server was used in an attack or operated by the same group.\n\nThe breaches affected Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank and Hyundai Capital, Yonhap reported. The [Wall Street Journal](https://www.wsj.com/world/asia/hackers-use-chinese-ai-tool-to-hit-south-korean-banks-exposing-new-risk-5d4d3885?ref=runtimewire) reported that officials put the number of people whose information was stolen at 68,000. A [Korea Times account](https://www.koreatimes.co.kr/business/banking-finance/20261005/ai-powered-attacks-on-banks-expose-technological-lag-in-koreas-financial-cyber-defenses?ref=runtimewire) put the figure above 67,000 and said exposed details included names, contact information, resident registration numbers, annual income and loan limits.\n\nARTEX's connection to the attacks remains under investigation. On October 2nd, [Yonhap reported](https://www.yna.co.kr/amp/view/AKR20261002042351017?ref=runtimewire) that a server believed to have been involved in the Shinhan incident displayed an ARTEX-related Chinese-language page title. At that point, authorities had not confirmed that attackers had actually used the tool. The October 6th report said financial-sector attack IP addresses showed ARTEX traces and that South Korea's National Police Agency was investigating. The forensic clues do not establish that ARTEX autonomously carried out the intrusions or that its developer was involved.\n\n### The person behind the project\n\nThe public identity attached to ARTEX is the GitHub account Autumn-27. The repository and the author's public project descriptions show a focus on assembling a complete penetration-testing workflow. They do not verify a personal name, career history or company behind the software.\n\nIn a [project description posted in late July](https://github.com/ruanyf/weekly/issues/10911?ref=runtimewire), the account presented ARTEX as a system that takes a defined target and authorized scope, breaks work into tasks, lets agents investigate and execute tools, and makes the process visible to a human operator. The [repository README](https://github.com/Autumn-27/ARTEX?ref=runtimewire) describes a Go backend, a Next.js interface and a multi-agent architecture. Users configure an external language-model provider, including Anthropic or OpenAI, and the system coordinates agents with different roles across reconnaissance, vulnerability checks and attack-path planning. The project also provides an [online demo](https://artex-demo.vercel.app/?ref=runtimewire).\n\nARTEX attempts to organize and carry out a sequence of testing tasks. The project describes itself as software for learning, code study and local, isolated testing, and warns against testing live systems. Its source code is open under the AGPL-3.0 license. A warning in a README sets out the author's intended use; it cannot ensure that a downloaded or modified copy will be used that way.\n\nA server showing ARTEX-related text could indicate that the tool was installed or that its environment was present. It does not show which functions were used, whether they were modified, or whether an AI agent made the decisions attributed to it. Yonhap's October 2nd reporting likewise said actual use in the Shinhan attack had not been verified. The more expansive headline claim that hackers used the Chinese AI tool therefore goes beyond what the described forensic evidence proves.\n\n### The breaches and their impact\n\nThe South Korean incidents targeted multiple financial firms in quick succession. The Korea Times reported that attackers appeared to probe less-protected entry points, including systems used by employees, contractors and loan agents, instead of going straight through banks' core networks. It also reported that credential stuffing, which tests previously obtained usernames and passwords against other services, was among the suspected techniques.\n\nThe suspected entry points raise questions about the security of systems outside the banks' core networks. A tool that automates reconnaissance could help an attacker test more systems faster. That capability does not prove the tool found the vulnerabilities or caused the breaches. The confirmed impact is the exposure of customer information; investigators have not established ARTEX's role.\n\nAhnLab's Security Intelligence Center identified roughly 600 IP addresses around the world hosting ARTEX instances, according to [Yonhap's October 6th report](https://www.yna.co.kr/amp/view/AKR20261006118100017?ref=runtimewire). That number measures observed instances, not 600 attackers or 600 malicious operations. AhnLab cautioned that open-source tools can be deployed by attackers, legitimate red teams, penetration testers and researchers. The same report said some servers also hosted another security platform, CyberStrikeAI, while warning that shared hosting alone does not prove a common operator or campaign.\n\nARTEX's GitHub author made an offensive-security workflow publicly available and documented an intended local-testing boundary. Investigators are assessing evidence that the software's traces appeared in infrastructure linked to attacks on financial firms. The evidence does not make the project's maintainer an attack suspect or establish that AI performed the intrusions.\n\nFor financial institutions, the risk does not depend on ARTEX being proven responsible. Seven firms reported breaches, and exposed customer information can create risks of phishing or other follow-on fraud. Authorities have also pointed to the possibility of attackers seeking weaknesses in partner and contractor systems, where controls may differ from a bank's central network. The investigation will determine how the intruders got access and what role, if any, ARTEX played. Until then, the case documents a live breach; it does not demonstrate an AI-led bank attack.", "url": "https://wpnews.pro/news/ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches", "canonical_source": "https://runtimewire.com/article/south-korea-bank-breaches-artex-ai-probe", "published_at": "2026-10-06 23:03:01+00:00", "updated_at": "2026-10-06 23:19:08.632767+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "artificial-intelligence"], "entities": ["AhnLab", "ARTEX", "South Korea National Police Agency", "Shinhan Bank", "KB Kookmin Bank", "Hana Bank", "Hyundai Capital", "Autumn-27"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches", "markdown": "https://wpnews.pro/news/ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches.md", "text": "https://wpnews.pro/news/ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches.txt", "jsonld": "https://wpnews.pro/news/ahnlab-finds-artex-on-600-ips-as-police-probe-south-korean-bank-breaches.jsonld"}}