egov.mn
Монголоор унших
TechnologyAutomated

Chinese developer makes ARTEX AI agent closed-source after its use in South Korean bank hacks

The developer of ARTEX, an open-source AI penetration-testing agent, has halted public releases and made the project closed-source after CrowdStrike linked it, alongside Claude Code and other LLMs, to a data-theft campaign against South Korean financial firms.

Share
Illustration of the ARTEX AI pentesting tool and attacks on South Korean financial institutions (The Hacker News)
Illustration of the ARTEX AI pentesting tool and attacks on South Korean financial institutions (The Hacker News)

The Chinese developer of ARTEX has converted the AI agent to a closed-source project after cybersecurity firms identified it as a tool used in a recent cyberattack campaign against South Korean banks, Reuters reported from Seoul on October 9.

Developer’s statement. “Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided,” the developer, who uses the GitHub handle “Autumn-27”, wrote on the platform. The developer said ARTEX was originally meant to help enterprises conduct security risk testing and said they opposed any illegal use of the software. ARTEX’s GitHub page has been taken down, according to Reuters’ checks.

CrowdStrike’s findings. In an October 7 report, CrowdStrike said a campaign against South Korean financial organizations, active from late September to early October 2026, resulted in exfiltrated data. Threat actor-controlled open directories contained Claude Code session histories, ARTEX configuration files and Claude memory files. The ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend, supplemented by GLM-5.3 and Grok 4.6 for additional sessions. CrowdStrike assessed with moderate confidence that the actor is likely a Chinese speaker and financially motivated, without attributing the activity to a named adversary. Reuters reported CrowdStrike said the suspect was likely a China-based 26-year-old.

Impact and response. ARTEX is not a standalone large language model; it connects to external LLMs such as ChatGPT, Claude and DeepSeek to automate penetration testing. At least nine South Korean banks have disclosed or been reported by local media as targets of cyberattacks since late September, prompting police to launch a probe this week and President Lee Jae Myung to call for robust response measures, Reuters said. The Hacker News also covered the campaign.

CrowdStrike said the activity shows how AI tooling can enable a financially motivated actor to conduct multiple intrusions within a short time span.

Share

Related articles