Lone Threat Actor Leverages Open-Source AI Stack to Attack South Korean Banks
A single threat actor reportedly orchestrated a major cyberattack targeting several of South Korea's largest banks using a combined stack of AI tools. The attack leveraged the open-source autonomous penetration testing framework ARTEX alongside an ensemble of LLMs including DeepSeek v4.1-Flash, GLM-5.3, Grok 4.6, and Claude Code. This incident highlights how agentic AI tools can amplify the capabilities of a single individual, allowing solo threat actors to execute complex operations previously requiring entire cybercrime groups. It signals a critical shift in cybersecurity threat models as automated exploitation frameworks become easily accessible to bad actors. According to CrowdStrike intelligence, the attacker integrated ARTEX—a Go-based self-hosted autonomous pentesting system—with multi-model LLM agents to plan and execute attack paths against financial networks. The multi-model ensemble approach allowed the offensive agents to reason, select tools, and bypass technical hurdles autonomously during the breach attempt.
## BACKGROUND
ARTEX is an open-source autonomous penetration testing platform built in Go that connects LLM agents to security tools for automated scanning and vulnerability exploitation. Agentic AI refers to systems that combine large language models with tool integrations and workflows, allowing software to independently plan, reason, and act toward specific goals rather than simply generating prompt responses.