Chinese Developer Closes ARTEX AI Agent After South Korean Bank Cyberattacks

Cyberattacks targeted at least nine South Korean banks aimed at stealing customers' personal data, affecting banking customers' financial security and privacy.
The same capabilities that defend can be repurposed for theft
ARTEX was designed to help companies find security weaknesses, but someone used it to break into banks and steal customer data.
Mark

So the developer just shut it down after the attacks were discovered? That seems reactive rather than preventive.

Mimi

Completely reactive. The tool was already out there, already downloaded, already forked. Closing it now doesn't undo what happened to those nine banks or recover the stolen data.

Luke

We should be careful here—Crowdstrike identified the suspect as a 26-year-old based in China, but that's one firm's assessment. We don't have independent confirmation of identity or nationality.

Mimi

Fair point. But the attacks themselves are confirmed—nine South Korean banks, customer data targeted, police investigation launched, presidential response. That part is solid.

Mark

Why would a developer release a penetration testing tool openly if they knew it could be misused?

Mimi

Because penetration testing is a legitimate security practice. Defensive teams need these tools. The developer probably assumed responsible use, or didn't anticipate how accessible it would be to someone with malicious intent.

Luke

And that's the real tension—open-source security tools live in this gray zone. They're necessary for the security community, but they're also blueprints for attack. There's no perfect answer.

Mark

Does closing it now actually matter?

Mimi

Symbolically, yes. It signals the developer takes responsibility. Practically, probably not much. The code is already out there, copied, forked, archived in a dozen places.

Luke

The bigger question is whether this changes how security tools get developed and distributed going forward. One incident doesn't usually shift an entire ecosystem's practices.

Mark

What about the developer's liability?

Mimi

They disclaimed responsibility for illegal use, which is standard. But there's a philosophical question underneath: if you build a tool you know can be weaponized, do you bear some responsibility for how it's used?

Luke

Legally, probably not in most jurisdictions. Ethically, that's messier and depends on who you ask.

  • ARTEX, an open-source AI penetration testing tool, converted to closed-source after cyberattacks on South Korean banks
  • At least nine South Korean banks targeted since late September; attacks aimed at stealing customer personal data
  • Suspect identified as 26-year-old based in China; used ARTEX and Anthropic's Claude Code
  • Developer (GitHub handle "Autumn-27") announced no further public updates or maintenance support

ARTEX, an open-source AI agent for security testing, has been converted to closed-source following its use in attacks on at least nine South Korean banks since late September. A China-based 26-year-old suspect allegedly used ARTEX and Anthropic's Claude Code to steal customer personal data, prompting police investigation and presidential intervention.

Chinese developer closes ARTEX AI agent to public after cybersecurity firms linked it to cyberattacks targeting South Korean banks. The tool was designed for penetration testing but allegedly misused in data theft campaigns.

On Thursday, the developer behind ARTEX, an artificial intelligence tool designed to test computer networks for security weaknesses, announced the project would no longer be available to the public. The decision came after cybersecurity researchers traced the tool to a series of coordinated attacks on South Korean banks that began in late September, with at least nine institutions reporting or being reported by local media as targets of the campaign.

ARTEX was released on GitHub earlier this year as an open-source project—meaning its code was freely available for anyone to download and modify. Unlike a standalone AI system, it functioned as an intermediary, connecting to larger language models like ChatGPT, Claude, and DeepSeek to automate the process of penetration testing, the practice of deliberately probing networks to find vulnerabilities before malicious actors can exploit them. The tool was built with legitimate purposes in mind: helping companies and organizations identify and fix security gaps in their systems.

But someone weaponized it. On Wednesday, Crowdstrike, a major American cybersecurity firm, identified the suspect behind the South Korean bank attacks as a 26-year-old based in China who had used ARTEX alongside Anthropic's Claude Code to break into banking systems and steal customer personal data. The attacks prompted South Korea's police to launch an investigation this week, and President Lee Jae Myung called for a forceful government response.

The developer, who operates under the GitHub username "Autumn-27," responded by shutting the door. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source," they wrote on the platform. "No further versions will be released to the public nor will maintenance support be provided." The developer stated that ARTEX was originally intended to help enterprises strengthen their security posture, and they opposed any illegal use of the software. They also disclaimed responsibility for conduct that breaks laws and regulations. By the time the announcement was made, ARTEX's GitHub page had already been taken down.

The incident sits at an uncomfortable intersection of open-source culture and security risk. Tools designed to find vulnerabilities are inherently dual-use—the same capabilities that let a defensive security team protect a bank can be repurposed by someone with different intentions. The developer's decision to close the project reflects a calculation that the reputational and legal exposure from continued public availability outweighed the benefits of maintaining an open-source project.

China's foreign ministry, when asked about the case at a regular briefing on Thursday, said it was unfamiliar with the specifics but reiterated that the country consistently opposes hacking activities. The statement offered no acknowledgment of the suspect's alleged nationality or the use of tools developed within China's tech ecosystem.

What remains unresolved is whether closing ARTEX after the fact will meaningfully reduce the risk. The code has already been distributed, forked, and copied across the internet. The developer cannot recall every version or prevent someone who downloaded it months ago from continuing to use it. The real question is whether this moment—a tool built for defense repurposed for theft, affecting millions of banking customers across an entire country—will prompt a broader reckoning about how open-source security tools are governed, who bears responsibility when they are misused, and what safeguards might prevent the next incident.

Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided.
— ARTEX developer (GitHub handle "Autumn-27")
China consistently opposes and combats hacking activities.
— Chinese foreign ministry spokesperson Mao Ning
Fale Conosco FAQ