Chinese AI tool ARTEX goes closed-source after use in South Korean bank cyberattacks

Cyberattacks targeted at least nine South Korean banks aimed at stealing customers' personal data.
Tools built to test defenses become weapons when pointed outward.
ARTEX was designed for legitimate security testing but was allegedly weaponized to breach South Korean banks.
Mark

So ARTEX was built to help companies find their own security problems. Why would shutting it down stop someone from using it to attack banks?

Mimi

It won't, really. The code was already out there for months. But the developer is essentially saying: I'm not maintaining this anymore, I'm not supporting it, and I'm taking my GitHub page down. It's a statement, not a technical solution.

Luke

Right, and we should be clear about what we actually know versus what we're inferring. Crowdstrike says a 26-year-old in China used ARTEX in the attacks. That's their assessment. We don't have independent confirmation of that attribution, and we don't know if the developer Autumn-27 had any connection to the attacker.

Mimi

Fair point. The developer's statement doesn't even acknowledge the South Korean banks by name. They just say the tool was misused and they're shutting it down.

Mark

But nine banks were hit. That's a lot of damage in one campaign. How did one person compromise that many institutions?

Luke

We know ARTEX connects to larger language models like ChatGPT and Claude. So the attacker had access to those tools plus ARTEX's automation capabilities. That's a powerful combination for finding and exploiting vulnerabilities at scale. But the reporting doesn't detail exactly how the attacks worked or what vulnerabilities were exploited.

Mimi

The goal was to steal customer personal data. That's what the banks disclosed. Whether the attacker succeeded in getting that data, or how much, isn't specified in what we have.

Mark

And China's foreign ministry just said they don't know anything about it?

Luke

They said they weren't familiar with the case and that China opposes hacking. That's a standard response. It doesn't confirm or deny anything about the developer's location or identity.

Mimi

The real question is whether this shuts down the threat or just moves it underground. The code exists. Copies are probably already circulating. Closing the GitHub page is symbolic more than practical.

Mark

So what happens next?

Luke

South Korean police are investigating. We'll likely see more details emerge about how the attacks worked and whether the attacker is identified or caught. But for now, we're working with Crowdstrike's assessment and the developer's response.

  • At least nine South Korean banks were targeted in late September by cyberattacks aimed at stealing customers' personal data, prompting a national police investigation and a presidential call for urgent countermeasures.
  • Crowdstrike identified a 26-year-old China-based suspect who allegedly weaponized ARTEX alongside Anthropic's Claude Code — turning a defensive security tool into a coordinated instrument of financial intrusion.
  • The developer behind ARTEX moved swiftly to shut down the project, converting it to closed-source and removing its GitHub page, while disclaiming responsibility for uses that violate law.
  • China's foreign ministry denied familiarity with the case and reiterated its opposition to hacking, offering no direct response to the attribution of the attacks to a China-based individual.
  • Security researchers warn that the code may already be copied or archived elsewhere, leaving the closure as a symbolic act rather than a guaranteed containment of the threat.

A tool built to strengthen digital defenses has become a reminder that in the architecture of security, the same key that locks a door can open it. ARTEX, an open-source AI agent released by a Chinese developer to automate penetration testing, was identified by Crowdstrike as the instrument behind coordinated cyberattacks on at least nine South Korean banks in late September 2026 — allegedly wielded by a 26-year-old based in China to extract customer data. The developer has since shuttered the project and sealed its code from public view, a gesture of accountability that raises the older, unresolved question of whether closing a door after it has been walked through offers any real shelter.

A Chinese developer has closed down an AI security tool after researchers linked it to a wave of cyberattacks on South Korean banks. The tool, ARTEX, was released earlier this year on GitHub under the username Autumn-27 as an open-source agent designed to automate penetration testing — the legitimate practice of probing systems for vulnerabilities before malicious actors can exploit them. Rather than functioning as a standalone AI, ARTEX acted as an intermediary, connecting to large language models like ChatGPT, Claude, and DeepSeek to systematically test network defenses.

In late September, at least nine South Korean banks reported being targeted in attacks aimed at extracting customer personal data. South Korean police opened an investigation, and President Lee Jae Myung called for robust countermeasures. Crowdstrike attributed the attacks to a 26-year-old based in China who had paired ARTEX with Anthropic's Claude Code to breach multiple financial institutions simultaneously.

Autumn-27 responded by announcing that ARTEX would receive no further updates, maintenance, or public distribution, and that the project's code would be converted to closed-source. The GitHub page has since been removed. The developer expressed opposition to illegal use but stopped short of directly addressing the South Korean incidents. China's foreign ministry, for its part, said it was unfamiliar with the case and reiterated the country's stated opposition to hacking.

The episode crystallizes a tension that has long shadowed open-source security research: tools built to defend can be turned to attack, and once released into the world, they are difficult to recall. Whether closing the source code will prevent further misuse is uncertain — archived copies may already circulate beyond the developer's reach. What remains clear is that the line between a security instrument and a weapon is drawn not in the code itself, but in the intent of whoever holds it.

A Chinese developer has shuttered an artificial intelligence tool after security researchers traced it to a coordinated attack on South Korean banks. The developer, operating under the GitHub username Autumn-27, announced Thursday that ARTEX—an AI agent designed to automate penetration testing—would no longer be maintained, updated, or distributed publicly. The project has been converted to closed-source code, meaning the underlying software is no longer accessible to the general public.

ARTEX was released on GitHub earlier this year as an open-source tool intended to help organizations identify security vulnerabilities in their networks. The system does not function as a standalone artificial intelligence model. Instead, it operates as an intermediary that connects to larger language models—including OpenAI's ChatGPT, Anthropic's Claude, and DeepSeek—to automate the process of testing computer systems for weaknesses. The stated purpose was legitimate: enabling enterprises and organizations to conduct their own security assessments and strengthen their defenses.

But in late September, the tool took on a different role. At least nine South Korean banks disclosed or were reported by local media to have been targeted in cyberattacks aimed at extracting customer personal data. The scale prompted South Korean police to launch an investigation this week, and President Lee Jae Myung called for comprehensive response measures. Crowdstrike, a major U.S. cybersecurity firm, identified the likely perpetrator on Wednesday: a 26-year-old based in China who had weaponized ARTEX alongside Anthropic's Claude Code to breach the banks' systems.

In his statement on the code-hosting platform, Autumn-27 acknowledged the misuse without directly naming the South Korean incidents. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source," the developer wrote. "No further versions will be released to the public nor will maintenance support be provided." The developer also stated opposition to any illegal use of the software and disclaimed responsibility for conduct that violates laws and regulations. ARTEX's GitHub page has since been removed.

The incident illustrates a recurring tension in open-source software development: tools created for defensive purposes can be repurposed for attack. Penetration testing itself is a legitimate security practice—organizations hire specialists to probe their own systems to find problems before malicious actors do. But the same techniques and tools can be turned outward, toward targets that have not consented to being tested. When ARTEX was paired with advanced language models, it apparently became capable enough to compromise multiple financial institutions simultaneously.

China's foreign ministry spokesperson Mao Ning addressed the matter Thursday at a regular press briefing, stating that the ministry was unfamiliar with the case. The spokesperson reiterated that China consistently opposes and combats hacking activities. The statement offered no direct response to Crowdstrike's attribution of the attacks to a China-based individual, nor did it address whether the developer Autumn-27 is known to Chinese authorities.

The closure of ARTEX marks an abrupt end to a project that had been in circulation for less than a year. Whether converting it to closed-source will prevent further misuse remains uncertain—the code may already be copied and distributed through other channels, and determined actors could potentially reverse-engineer or modify archived versions. The incident has nonetheless sent a signal through the security research community: tools designed to test defenses can become weapons, and developers may face pressure to restrict access when their creations are weaponized, regardless of original intent.

Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided.
— Autumn-27, ARTEX developer, on GitHub
China consistently opposes and combats hacking activities.
— Mao Ning, Chinese foreign ministry spokesperson
Möchten Sie die ganze Geschichte? Das Original lesen bei The Hindu ↗
Kontakt FAQ