Executive Summary
Beginning in late September 2026, a series of cyberattacks targeted major South Korean financial institutions, including KB Kookmin, Shinhan, and Hana Bank. The campaign involved the misuse of ARTEX, an autonomous 'agentic' penetration testing tool developed by a Chinese entity (Autumn-27). By leveraging large language models (LLMs) such as DeepSeek v4.1-flash, Claude, and Grok, the attackers automated vulnerability discovery and credential stuffing, resulting in the exfiltration of tens of thousands of personal data records.
Technically, the threat actor utilized a two-server architecture, with primary command-and-control operations routed through Hong Kong and automated attack instances hosted on separate infrastructure. While one specific Brazilian actor group, SCARLET LOOP, was identified using similar agentic methodologies for scale-based credential stuffing, the primary South Korean activity remains attributed to a suspected Chinese-speaking, financially motivated operator identified by the handle 'YY520CN'.
This activity marks a critical evolution in adversary tradecraft where autonomous AI agents reduce the cost and technical barrier for high-tempo, multi-target intrusions. The impact on the South Korean financial sector was immediate, leading to emergency government inspections and the subsequent closure of the ARTEX open-source project by its developer due to widespread abuse.
