TGViewer
SITREP - Independent OSINT Channel SITREP - Independent OSINT Channel @sitreports · 23K subscribers
Post #39565 228
🤖 AI-assisted intrusion chain exposed in South Korean bank attacks

A Chinese-speaking threat actor used ARTEX AI and Claude agents in attacks against multiple South Korean banks, including Shinhan, KB Kookmin, and Hana. CrowdStrike traced open directories containing Claude session histories, ARTEX configs, and memory files, linking the infrastructure to breaches that exposed customer data and in some cases disrupted systems.

The case shows agentic tooling moving from lab-grade pentest automation into operational intrusion support. It also highlights a recurring OPSEC failure: AI workflow artifacts can preserve target lists, tool settings, and operator traces that materially improve attribution and incident reconstruction.

🛰️ Open sources - closed narratives
@sitreports
More from @sitreports
  1. Oct 11, 2026🔍 Cyber executive arrested in sealed US extortion case Canadian cybersecurity executive E…
  2. Oct 11, 2026🔍 Third-party AI agents widen enterprise blind spots A new analysis argues that AI securi…
  3. Oct 11, 2026🤖 Anthropic Restricts Live Web Access in Internal Claude Testing Anthropic has cut live i…
  4. Oct 11, 2026📡 Iran-linked DNS tunneling spike generated 40 billion passive DNS records DomainTools di…
  5. Oct 11, 2026📡 DarkBlinders campaign uses fake meeting client and GitHub C2 DarkBlinders ran a cyberes…
  6. Oct 11, 2026🔍 AhsayCBS zero-days enable unauthenticated SYSTEM access on backup servers Threat actors…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →