Science & Tech · Cybersecurity · 1 day ago
ARTEX developer halts public updates after reports of use in Korean bank attacks
ARTEX is a Chinese-developed tool designed to help test computer systems for security weaknesses.
It connects to large language models so an AI agent can examine targets, plan ways into systems and run security tools.
US cybersecurity firm CrowdStrike said attackers used ARTEX alongside an AI model in attacks on South Korean financial institutions from late September to early October.
The developer, using the name Autumn-27, said updates would stop, future versions would not be released publicly and maintenance support would end.
The developer did not directly refer to the Korean attacks, but said the tool had been misused and opposed illegal use.
The tool’s GitHub page was reported to have disappeared, which may make it harder for new users to get the code.
Copies already downloaded cannot be recalled, so the change cannot by itself stop people from continuing to use them.
South Korean police have opened an investigation into the attacks and expanded the team handling the case.
The developer of ARTEX, an AI-assisted penetration-testing tool linked to attacks on South Korean financial institutions, said the project would stop receiving updates and move to private source code.
The developer, known on GitHub as Autumn-27, said no further versions would be released publicly and maintenance support would end.
The tool’s GitHub page was reported to have disappeared, but experts said this would not remove copies already downloaded or prevent their continued use.
CrowdStrike said attackers had used ARTEX together with large language models in attacks targeting South Korean financial institutions.
A person identified by CrowdStrike as a possible participant denied involvement, while the reported identity and role of the attacker remain unconfirmed.
- Who
- ARTEX developer Autumn-27; attackers suspected of targeting South Korean financial institutions; and CrowdStrike.
- What
- The ARTEX developer announced an end to public updates, releases and maintenance, and a move to private source code.
- When
- The developer announced the decision on October 8, 2026.
- Where
- The attacks targeted financial institutions in South Korea; the announcement was posted on GitHub.
- Why
- The developer cited misuse of the tool and said it opposed illegal use.
CrowdStrike
YY
Alleged involvement in the attacks
CrowdStrike
CrowdStrike raised the possibility that a 26-year-old person in China was involved in the attacks and said evidence suggested ARTEX and Anthropic’s Claude Code had been used.
YY
The Telegram account user identified as YY denied involvement and said someone had framed them.
Identity and evidence
CrowdStrike
CrowdStrike’s identification was based on AI chat records, according to the report.
YY
The report said the person’s identity and whether they were actually the attacker had not been confirmed.
Considering the misuse of the tool, ARTEX will no longer be updated and will become private source code.
New versions will not be released to the public, and maintenance support will not be provided.
Someone framed me.
A series of cyberattacks targeting South Korean financial companies reportedly took place.
South Korean police formally opened an investigation into the financial-sector attacks.
CrowdStrike reported that ARTEX and Claude Code appeared to have been used in attacks targeting South Korean banks.
ARTEX developer Autumn-27 announced that updates and public releases would stop and the source code would become private.
Police expanded the dedicated investigation team from 28 to 43 members, according to Donga Ilbo.
- Tool
- ARTEX, an AI-assisted penetration-testing program that connects to external large language models.
- Developer
- Autumn-27, the developer’s name on GitHub.
- Announcement
- October 8, 2026, on GitHub.
- Police investigation team
- Expanded from 28 to 43 members on October 9, 2026.
- Suspect attribution
- CrowdStrike raised the possibility that a 26-year-old person in China was involved; the identification was not confirmed.











