AI Affairs, home

Friday 9 October 2026

News

ARTEX developer says AI agent will go closed-source after Korean bank hacks

The developer says public releases and maintenance will end. CrowdStrike links the penetration-testing agent and Anthropic’s Claude Code to attacks targeting South Korean bank customers’ data.

Turquoise network cables plugged into server patch panels in a data center
Photo: Brett Sayles via Pexels

The developer behind ARTEX said on 8 October that the AI agent would become closed-source after cybersecurity firms identified it in attacks on South Korean banks, Reuters reported. Public releases and maintenance of the penetration-testing tool will end, according to the developer.

Key points

  • ARTEX developer Autumn-27 says the project will become closed-source and public updates will stop.
  • CrowdStrike says a suspected attacker used ARTEX and Anthropic’s Claude Code against South Korean banks.
  • Reuters reports at least nine banks have been targeted since late September.

Autumn-27 ends public ARTEX releases

The developer, who uses the GitHub handle Autumn-27, said ARTEX would receive no more public versions or maintenance support. They attributed the decision to misuse of the tool. Reuters found that the project’s GitHub page had been taken down.

Autumn-27 said they had built ARTEX to help organisations test security risks and improve their defences. They said they opposed illegal use of the software and accepted no responsibility for conduct that breaches laws and regulations.

ARTEX was released on GitHub earlier in 2026 as an open-source agent that automates penetration testing. It connects to external large language models, including ChatGPT, Claude and DeepSeek, to help organisations find weaknesses in their networks.

CrowdStrike identifies ARTEX and Claude Code

CrowdStrike said on 7 October that the suspected attacker behind recent attempts to steal South Korean bank customers’ personal data was likely a 26-year-old based in China. The cybersecurity firm said the person used ARTEX alongside Anthropic’s Claude Code.

South Korea’s Financial Security Institute traced attack IP addresses and server logs associated with a Shinhan Bank breach and found signs of ARTEX, Startup Fortune reported, drawing on the Korea Herald. The tool had been published with Chinese-language documentation.

At least nine South Korean banks have disclosed attacks or been reported as targets by local media since late September, Reuters reported. Tech Insider put the number of financial institutions reporting hacking-related personal information leaks at at least seven.

Startup Fortune reported roughly 65,000 customer records exposed across the breaches. Tech Insider put the combined exposure at roughly 68,000 people, drawing on figures it attributed to Firstpost and the Wall Street Journal.

South Korea probes the bank attacks

South Korean police launched a probe, while President Lee Jae Myung called for a robust response. AI Affairs reported Lee’s order to investigate the bank hacks amid questions about AI use.

South Korea’s Financial Supervisory Service identified 19 attacker IP addresses across 12 countries, including the United States, Japan, Hong Kong, Singapore and Vietnam, Startup Fortune reported, drawing on Korea JoongAng Daily.

Chinese foreign ministry spokesperson Mao Ning said at a briefing on 8 October that the ministry was unfamiliar with the case and that China consistently opposed and fought hacking activities.

Sources

Topics: Agents, Financial services, Safety