ARTEX Developer Closes AI Hacking Tool After Bank Attacks
The developer said the penetration-testing agent will no longer be publicly maintained after researchers linked it to attacks on South Korean banks.
Topics
News
- Fired OpenAI Researchers Warn Dismissals Could Chill Safety Work
- ARTEX Developer Closes AI Hacking Tool After Bank Attacks
- AI Redraws Global Race for Quant Talent as Coding Tools Lower Entry Barriers
- AI Dispatch | India Draws Billions Into AI
- AI Bots Now Make Up Half of Traffic to US Fed’s FRED Database
- Musk Blames ‘Oligarchs’ For Delay in Starlink’s India launch
The developer of ARTEX, an AI-powered penetration-testing tool linked to cyberattacks on South Korean banks, has taken the project closed source and said no further public versions will be released.
The developer, who uses the GitHub handle Autumn-27, announced the decision on Thursday after cybersecurity researchers identified ARTEX among the tools used in attacks on South Korea’s financial sector.
“Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided,” the developer wrote on GitHub.
The ARTEX GitHub page was subsequently taken down, Reuters said.
ARTEX was released as an open-source agent to automate parts of penetration testing. It is not a standalone large language model. Instead, it can connect with models including Claude, ChatGPT and DeepSeek to help identify and test vulnerabilities in computer networks.
The developer said ARTEX had originally been intended to help companies and other organizations assess security risks and improve their defenses. Without directly addressing the South Korean bank attacks, they said they opposed illegal use of the software and did not accept responsibility for activity that violated laws or regulations.
The decision follows findings from US cybersecurity company CrowdStrike, which said this week that a suspected attacker targeting South Korean financial institutions used ARTEX alongside Anthropic’s Claude Code.
CrowdStrike said its investigation pointed with moderate confidence to a Chinese-speaking, financially motivated attacker and identified information suggesting the operator could be a 26-year-old based in Guangdong province. The company has not attributed the attacks to a named hacking group or the Chinese government.
At least nine South Korean banks have disclosed attacks or have been reported by local media as targets since late September. The incidents have prompted a police investigation and calls from President Lee Jae Myung for stronger measures to protect the financial sector.
Asked about the case on Thursday, Chinese foreign ministry spokesperson Mao Ning said the ministry was not familiar with the matter and reiterated that China opposes and combats hacking activity.
The withdrawal of ARTEX from public development highlights a growing problem for security tools built with AI.


