Chinese AI tool ARTEX goes closed-source after South Korean bank hack

Cyberattacks targeted at least nine South Korean banks aimed at stealing customers' personal data.
Tools built for defense repurposed for theft
ARTEX, designed to help organizations test security, was weaponized in attacks targeting South Korean banks.
Mark

So the developer just shut it down? That seems like an admission of something.

Mimi

Not quite. They're saying they built it for security testing—which is real—and that they don't support illegal use. But yes, once it was linked to actual bank attacks, keeping it public became untenable.

Luke

But we should be careful here. Crowdstrike identified the suspect and the tool. We don't have confirmation from South Korean authorities yet, and we don't know if ARTEX was the only vector or just one piece of the attack.

Mark

Nine banks is a lot though. That's not a small incident.

Mimi

It is. And it prompted a police investigation and a presidential statement. The scale is real. But Luke's right—we know Crowdstrike's assessment, not necessarily the full technical picture.

Mark

Why would a developer release something like this if they knew it could be misused?

Mimi

That's the open-source dilemma. The tool itself is legitimate. Penetration testing is how companies find their own weaknesses. The developer probably didn't anticipate it being used this way, or thought the legitimate use case outweighed the risk.

Luke

And we should note: we don't have a direct quote from the developer explaining their thinking. We have a GitHub statement. We don't know if they're cooperating with anyone or if there's an investigation into them.

Mark

What about the Chinese government angle?

Mimi

The foreign ministry said they don't know about it and oppose hacking. That's the standard response.

Luke

Which tells us nothing about whether they're investigating the suspect or whether this was state-sponsored. Those are still open questions.

  • At least nine South Korean banks have been breached since late September, with customer personal data extracted in what investigators are treating as a coordinated campaign.
  • Crowdstrike identified a 26-year-old China-based suspect who combined ARTEX with Anthropic's Claude Code to penetrate financial institutions — a pairing of legitimate AI tools repurposed for criminal ends.
  • South Korean police launched a formal investigation and President Lee Jae Myung called for a sweeping government response, signaling that the attacks have risen to the level of a national security concern.
  • The developer Autumn-27 pulled ARTEX from public access and converted it to closed source, issuing a careful legal disclaimer while stopping short of naming the South Korean attacks directly.
  • China's foreign ministry distanced Beijing from the incident with a brief statement opposing hacking in principle, offering no indication of domestic investigation or cross-border cooperation.

When a Chinese developer quietly closed the doors on an open-source AI security tool called ARTEX, the act marked more than a single project's end — it illuminated the ancient tension between a tool's intended purpose and its actual use. Since late September, cybersecurity researchers traced ARTEX to coordinated breaches of at least nine South Korean banks, allegedly carried out by a 26-year-old in China who turned a defensive instrument into a weapon for theft. The episode asks a question that technology alone cannot answer: who bears responsibility when a creation built to protect becomes the means of harm?

A Chinese developer known as Autumn-27 has shut down the public version of ARTEX, an AI-powered penetration testing platform, after cybersecurity researchers linked it to a series of attacks on South Korean financial institutions. The decision was announced on GitHub on Thursday, with the developer stating that the project would be converted to closed source and receive no further updates. The ARTEX page has since been removed entirely.

ARTEX was not itself a large language model but an automation layer designed to connect to existing AI systems — among them ChatGPT, Claude, and DeepSeek — to help organizations probe their own networks for weaknesses. Released earlier this year as an open-source project, its stated purpose was defensive. That purpose did not hold.

Crowdstrike identified the person behind the South Korean attacks as a 26-year-old based in China who used ARTEX alongside Anthropic's Claude Code to breach at least nine banks and extract customer data. The scale of the intrusions prompted South Korean police to open an investigation and the country's president to call for a coordinated government response.

Autumn-27's statement on GitHub disclaimed responsibility for illegal use and expressed opposition to it — language that was precise without being candid, distancing the developer from consequences without acknowledging the attacks by name. China's foreign ministry offered a similarly measured response, stating only that Beijing opposes hacking as a matter of policy and that it was unfamiliar with the case.

The incident crystallizes two problems that the cybersecurity world has long struggled to resolve: the dual-use nature of security tools, which can defend or destroy depending on who wields them, and the diffuse accountability that follows when open-source software crosses borders and causes harm.

A Chinese developer has shuttered the public version of ARTEX, an artificial intelligence tool designed to test computer networks for security weaknesses, after cybersecurity researchers traced it to a series of attacks on South Korean banks. The developer, known on GitHub as Autumn-27, announced the decision on Thursday, stating that ARTEX would no longer receive updates and would no longer be available to the public. The move came after the tool was identified as part of a coordinated campaign to breach at least nine South Korean financial institutions since late September.

ARTEX is not a standalone artificial intelligence system but rather an automation platform that connects to existing large language models—including OpenAI's ChatGPT, Anthropic's Claude, and DeepSeek—to help organizations identify vulnerabilities in their networks. Released on GitHub earlier this year as an open-source project, it was built with a stated purpose: to enable companies and institutions to conduct security testing and strengthen their defenses. The developer's announcement made clear that this legitimate use case had been overtaken by something else entirely.

Crowdstrike, the American cybersecurity firm, identified the person behind the South Korean bank attacks as a 26-year-old based in China who wielded ARTEX alongside Claude Code, Anthropic's coding assistant, to target financial institutions and extract customer personal information. The scope of the breach was substantial enough to prompt South Korean police to launch an investigation this week and President Lee Jae Myung to call for a comprehensive government response. The attacks represented a stark illustration of how tools built for defensive purposes can be repurposed for theft and fraud.

In a statement posted to GitHub, Autumn-27 said the project would be converted to closed source, meaning the code would no longer be publicly accessible and no further versions would be released. The developer also stated they opposed any illegal use of the software and disclaimed responsibility for violations of law. The ARTEX GitHub page itself has since been removed. The language was careful and legalistic—a developer distancing themselves from the consequences of their creation without directly acknowledging the South Korean attacks by name.

China's foreign ministry spokesperson Mao Ning told reporters on Thursday that the ministry was unfamiliar with the case, while reiterating that China opposes hacking activities as a matter of policy. The statement offered no additional detail and did not address whether Chinese authorities were investigating the suspect or cooperating with South Korean investigators. The incident sits at the intersection of two persistent tensions in cybersecurity: the dual-use problem, where tools built for legitimate defense can be weaponized for attack, and the question of responsibility when open-source software is misused across borders.

Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public.
— Autumn-27, ARTEX developer, on GitHub
China consistently opposes and combats hacking activities.
— Mao Ning, Chinese foreign ministry spokesperson
Vuoi la storia completa? Leggi l'originale su Livemint ↗
Contattaci Domande frequenti