1 hr ago
ARTEX Developer Closes AI Agent After South Korean Bank Attacks
ARTEX is a computer tool made to help organizations test their computer security.
It could use other AI services to help look for weaknesses.
A cybersecurity company said a person suspected of attacking South Korean banks likely used ARTEX and Claude Code.
The attacks were aimed at stealing customers' personal information, according to the report.
ARTEX's developer said the tool was misused and announced it would no longer be updated or supported.
The developer also said they opposed illegal use and were not responsible for unlawful actions.
At least nine South Korean banks were reported as targets since late September.
Police are investigating, and South Korea's president called for a strong response.
ARTEX's developer, using the GitHub handle Autumn-27, said Thursday the project would become closed-source and receive no further public versions or maintenance.
The developer said ARTEX was created to help organizations test security risks and opposed illegal use of the software.
CrowdStrike said a suspect in recent attacks on South Korean banks likely used ARTEX and Anthropic's Claude Code.
ARTEX was an open-source agent for automating penetration tests and could connect to external AI models, including ChatGPT, Claude, and DeepSeek.
At least nine South Korean banks were disclosed or reported as attack targets since late September; police opened a probe, and President Lee Jae Myung called for a robust response.
- Who
- ARTEX developer Autumn-27; CrowdStrike identified a suspected attacker as likely China-based.
- What
- The developer announced ARTEX would become closed-source after cybersecurity firms linked it to attacks targeting South Korean banks.
- Where
- South Korea; ARTEX was hosted on GitHub, whose page has since been taken down according to Reuters' checks.
- When
- The announcement was made Thursday; CrowdStrike's statement came Wednesday. Attacks on banks were reported since late September.
- Why
- The developer cited misuse of the tool; the reported bank attacks aimed to steal customers' personal data.
Developer's position
Cybersecurity firm's assessment
ARTEX's connection to the attacks
Developer's position
The developer said they opposed illegal use of ARTEX and bore no responsibility for conduct violating laws and regulations.
Cybersecurity firm's assessment
CrowdStrike said the suspect in the South Korean bank attacks likely used ARTEX alongside Claude Code.
Key facts
- Project
- ARTEX, an AI agent designed to automate penetration testing
- Developer
- Autumn-27, a GitHub handle
- Project status
- To become closed-source, with no further public versions or maintenance support
- Reported tool use
- CrowdStrike said the suspect likely used ARTEX and Anthropic's Claude Code
- Banks targeted
- At least nine South Korean banks disclosed or reported as targets
- Investigation
- South Korean police launched a probe this week
- Suspect description
- CrowdStrike said the suspect was likely a China-based 26-year-old
Quotes
Autumn-27
Chinese developer of ARTEX, identified by their GitHub handle.
“Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided.”
livemint.com









