What happened
The Chinese developer of ARTEX, an open-source for automated penetration testing, announced on October 8 that the project is being converted to closed-source and will no longer be updated or maintained. This decision follows cybersecurity reports identifying ARTEX as a tool used in a campaign of cyberattacks against South Korean banks. The developer stated they oppose illegal use and bear no responsibility for such conduct. The ARTEX GitHub page has been taken down. US firm CrowdStrike previously reported that the suspect behind the attacks likely used ARTEX alongside Anthropic’s Claude Code. At least nine South Korean banks have been targeted since late September, prompting a police probe and a presidential call for robust response measures. China’s foreign ministry stated it was not familiar with the specific case but reiterated its opposition to hacking activities.
On October 8, the developer of ARTEX, identified by the GitHub handle Autumn-27, announced that the project would be converted to closed-source. The developer stated that due to the misuse of the tool, no further versions would be released to the public, and maintenance support would cease. The ARTEX GitHub page was subsequently taken down, as confirmed by Reuters checks.
ARTEX is an open-source released on GitHub in 2026, designed to automate penetration testing. It is not a standalone large language model but connects to external LLMs such as ChatGPT, Claude, and DeepSeek to help organizations test for network vulnerabilities. The developer claimed the original aim was to help enterprises conduct security risk testing and improve security capabilities, while stating they opposed illegal use and bore no responsibility for conduct violating laws.
The decision follows reports from US cybersecurity firm CrowdStrike on October 7, which stated that the suspect behind recent cyberattacks at South Korean banks was likely a China-based 26-year-old who used ARTEX and Anthropic’s Claude Code. The attacks, which began in late September, targeted at least nine South Korean banks with the aim of stealing customers’ personal data.
In response to the attacks, South Korean police launched a probe, and President Lee Jae Myung called for robust response measures. China’s foreign ministry spokesperson Mao Ning stated on October 8 that the ministry was not familiar with the specific case but added that China consistently opposes and combats hacking activities.
Source details: straitstimes.com ↗
Why it matters
This move marks a significant shift in the availability of offensive AI security tools, as a widely accessible open-source agent is removed from public circulation following its documented use in high-profile financial cyberattacks. It highlights the growing tension between the open-source security community’s goal of improving defensive capabilities and the real-world risk of these tools being weaponized by state or non-state actors. The incident underscores the difficulty of controlling the downstream misuse of AI agents that connect to powerful external LLMs. For organizations, it signals that the threat landscape for AI-assisted penetration testing is evolving rapidly, with tools appearing and disappearing based on geopolitical and security events. The removal may limit the ability of defenders to study the specific vulnerabilities exploited, while potentially reducing the immediate availability of the tool for malicious actors.
The closed-sourcing of ARTEX represents a concrete change in the availability of a specific AI security tool, directly linked to its use in a major cyber incident. This is not merely a policy discussion but a tangible removal of a resource from the public domain.
The incident highlights the dual-use nature of AI agents in cybersecurity. While intended for defensive risk testing, the tool was leveraged for offensive attacks, demonstrating the challenge of controlling the application of open-source AI technologies in high-stakes security contexts.
The involvement of a Chinese developer and the targeting of South Korean financial institutions adds a geopolitical dimension to the AI security landscape, potentially influencing international cooperation and regulatory responses regarding AI tooling.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?
What to watch next
Monitor for any mirrors or forks of the ARTEX codebase that may remain accessible despite the original repository’s removal. Watch for further statements from South Korean authorities or CrowdStrike regarding the identity of the suspect and the extent of data exfiltration. Observe whether other open-source AI security tools face similar restrictions or scrutiny following this incident. Track the response of the AI security community to the closed-sourcing of a tool originally intended for defensive risk testing.
Investigate whether the ARTEX codebase has been mirrored or forked on other platforms, which could undermine the effectiveness of the closed-source move.
Follow up on the South Korean police probe and any potential arrests or indictments related to the bank hacks, which may provide further details on the use of AI tools in the attacks.
Observe if other open-source AI security projects implement similar restrictions or if the incident leads to broader regulatory scrutiny of AI penetration testing tools.