ARTEX AI, the Chinese open-source penetration testing agent that investigators tied to a wave of South Korean bank breaches, has been pulled from public view. On Thursday 8 October 2026 its developer, who uses the GitHub handle “Autumn-27”, posted a short statement saying the tool had been “abused” by malicious actors and that the project would stop all updates and become closed-source. The repository that hosted the code now returns “Not Found”.

The move came one day after CrowdStrike published a report linking ARTEX AI to a campaign against South Korean lenders, and a few days after South Korea’s government said it was “highly likely” the tool was used in breaches at more than seven financial institutions. According to AFP, the Financial Services Commission puts the number of people affected at more than 68,000.

This article explains what ARTEX AI is, how it was linked to the Korean attacks, what the developer actually said, and why taking a tool private after release does little to stop it spreading. We also set out what UK law says about dual-use security tools and the practical steps UK businesses should take now. For the breach itself, see our earlier report on the AI banking hacks at seven South Korean lenders.

What Happened to ARTEX AI This Week

artex ai chinese tool pulled misuse south korea hacks d row of three beach huts with one door open

The developer’s statement appeared on the Autumn-27 GitHub profile page, not in the ARTEX repository itself. The commit history shows the profile README was edited at 10:50 UTC on 8 October. The same edit deleted a link titled “ARTEX: AI automated penetration testing system”, which had been added to the profile on 27 July.

AFP, Reuters and The Hacker News all quoted the statement within a day. Its core sentence, in AFP’s translation, reads: “Given the misuse of the tool, the Artex project will no longer be updated and will be converted to closed-source.” The developer added that “no further versions will be released to the public, nor will maintenance support be provided.”

The developer’s statement, point by point

The original is written in Chinese and signed “ARTEX author, 8 October 2026”. It makes three numbered points. Our translation of each is below.

First, “this malicious attack incident has nothing to do with the tool’s author”. ARTEX AI, the statement says, was designed “for learning and research”, to help companies and organisations carry out security testing “within the scope of authorised assets” and so improve their defences.

Second, the malicious use “completely goes against the author’s original intention”. The author “bears no responsibility” for any unauthorised or illegal use “and strongly condemns it”.

Third, “given the reality of the tool being abused”, the project will no longer be updated and will become closed-source, with no more public versions and no maintenance support. The statement ends with a reminder that “technology should be used for proper purposes” and a warning to users not to break the law.

What “closed-source” means in practice

Open-source software publishes its underlying code so anyone can download it, read it, change it and run it. Closing the source means the public repository disappears and future work, if any, stays private. Both the GitHub web page and the GitHub API now return “Not Found” for the ARTEX AI repository.

What closing the source cannot do is reach back in time. Every copy that was cloned, forked or mirrored between late July and early October still exists on someone else’s machine. The decision “cannot remove copies already downloaded or prevent people from continuing to use them”, Poe Zhao, founder of the analysis publication Hello China Tech, told AFP.

Why the timing matters

The statement did not mention South Korea, banks or CrowdStrike by name. It arrived, however, the day after CrowdStrike’s report and two days after South Korean President Lee Jae Myung told his cabinet that “signs have emerged of AI being used” in some of the hacking incidents. The developer’s own phrase, that the attack “has nothing to do with the tool’s author”, reads as a direct reply to that week’s coverage.

What ARTEX AI Is and Who Built It

artex ai chinese tool pulled misuse south korea hacks e sourdough starter jar bubbling over its rim

ARTEX AI is an agent, not a model. It does not contain its own large language model. Instead, it connects to outside models and hands them tasks, in the way a project manager splits work across a team. According to The Wall Street Journal, as reported by The Herald Business, it can call on Anthropic’s Claude, OpenAI’s ChatGPT and China’s DeepSeek “and deploy them like members of a team”.

Its purpose, on paper, is automated penetration testing: probing an organisation’s own systems for weaknesses before criminals find them. That is a legitimate and growing field. The problem is that a tool built to find and use weaknesses on request does exactly the same job for whoever is giving the requests.

An agent built by an established security developer

The WSJ named the developer as Li Puhua, a Chinese cybersecurity engineer who goes by “Autumn”. The Autumn-27 GitHub account was created in August 2019 and has around 600 followers. Its best-known project is ScopeSentry, an asset-mapping and scanning platform that has about 1,700 stars on GitHub, which makes this a known name in Chinese security circles rather than an anonymous throwaway account.

ARTEX AI was the newest project on the account. StartupFortune reports it was published on 26 July under the AGPL-3.0 open-source licence. The profile link to it appeared a day later.

The usage rules on the project page

Before it was taken down, the ARTEX AI page told users the software was meant for “personal learning, code research and local technical verification”, according to Reuters. It said the tool should not be used for real-world testing against online systems or websites.

The Herald Business reports that after the bank hacks came to light, the project added language that explicitly banned malicious uses such as unauthorised intrusion and data theft. As that report notes, written rules alone do little to stop someone who has already decided to commit a crime.

ARTEX AI at a glance

ItemDetailSource
What it isOpen-source, multi-agent penetration testing system driven by outside modelsCrowdStrike, WSJ
DeveloperGitHub handle Autumn-27; named by the WSJ as Li PuhuaGitHub, WSJ
PublishedLate July 2026 (26 July per StartupFortune; profile link added 27 July)GitHub commit history
LicenceAGPL-3.0StartupFortune
Models it can callClaude, ChatGPT, DeepSeek and othersWSJ, Reuters
Stated purposeLearning, research and authorised testing onlyDeveloper statement
Status on 9 OctoberRepository removed; project closed-source; no further releasesGitHub, AFP

How ARTEX AI Was Linked to the Korean Bank Hacks

artex ai chinese tool pulled misuse south korea hacks f fire bucket hanging on a wall bracket

Three separate lines of evidence point to the tool. None of them came from the developer, and only one was public at first.

The Financial Security Institute’s log trail

The first came from South Korea’s Financial Security Institute (FSI). On 3 October an FSI official told The Herald Business that investigators had traced the attack addresses and server logs at Shinhan Bank, the first lender to report a breach, and found evidence of ARTEX AI. “When you analyse the attack data, there is a specific data signature common to traffic originating from ARTEX, which allows us to identify the attacker,” the official said.

The same official stressed that a person, not the software, was in charge. “It is true that AI was used in the attacks, but the AI did not act independently without human involvement,” they said. “A hacker used the AI as a tool.”

What CrowdStrike found in the open directories

The second line came from CrowdStrike, whose intelligence team published a report on 7 October titled Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance. Its researchers found a server linked to the attacks that was hosting an ARTEX AI instance alongside an exposed directory that anyone could browse.

That directory led to a second, Hong Kong-based server holding more exposed files: Claude Code session histories, ARTEX AI configuration files and AI memory files. CrowdStrike says these showed the operator targeting South Korean financial organisations from late September to early October, and that the targets overlap with the firms named in local reporting.

CrowdStrike maps the operator’s use of the tool to the MITRE ATT&CK technique T1588.007, Obtain Capabilities: Artificial Intelligence. In short, the attacker’s own working notes were left where researchers could read them. The AI tooling that sped the attack up also wrote a detailed record of it.

The model stack behind the attacks

CrowdStrike says the ARTEX AI instance ran on DeepSeek v4.1-flash as its main model, the same model family we covered at launch in our report on DeepSeek V4.1 Flash. The operator added Zhipu AI’s GLM-5.3 and Grok 4.6 for further Claude Code sessions, and likely reached DeepSeek through a third-party API reseller rather than directly.

The Herald Business had reported on 6 October that the ARTEX AI developers added a DeepSeek-powered web search feature on 13 September. It also noted that the top four security agents on Tencent’s TSecBench leaderboard all use DeepSeek Flash as their base model.

Timeline: from release to closed-source

Date (2026)Event
26 to 27 JulyARTEX AI published on GitHub and linked from the developer’s profile
13 SeptemberDeepSeek-powered web search added, per Korean industry sources
27 Sept to 1 OctAttacks concentrated in this window, per the FSI
3 OctoberFSI confirms ARTEX traces in Shinhan Bank’s logs
6 OctoberPresident Lee raises AI use at cabinet; WSJ reports on the tool
7 OctoberCrowdStrike publishes its ARTEX report
8 OctoberDeveloper statement; repository removed and project made closed-source
19 OctoberHeads of five major banks due at a parliamentary audit, per The Register

Counting from the profile link on 27 July, the chart below shows how quickly events moved. It uses simple day counts: 4 days to the end of July, 31 in August and 13 in September gives 48 days to the search feature, and the closure on 8 October came on day 73.

Days after ARTEX AI was linked on GitHub (27 July = day 0; closure on day 73 = 100%)
Web search feature added (13 Sep) day 48
Attack window opens (27 Sep) day 62
FSI confirms traces (3 Oct) day 68
CrowdStrike report (7 Oct) day 72
Project made closed-source (8 Oct) day 73

Ten weeks from public release to a confirmed role in a national banking incident is fast. It is also roughly how long the code sat in the open for anyone to copy.

The Damage: Who Was Hit and What Leaked

artex ai chinese tool pulled misuse south korea hacks b chain link fence with a flap cut and peeled back

The Financial Services Commission says more than 68,000 people were affected. Shinhan Bank has said that information attached to loan applications for about 25,000 customers leaked, including names, phone numbers and annual income. The firm-by-firm figures below come from Korean disclosures we gathered for our earlier report, and they reconcile with the official total.

Records exposed by firm in the ARTEX AI-linked breaches (Yegaram Savings Bank = 100%)
Yegaram Savings Bank ~40,300
Shinhan Bank 25,729
Welcome Savings Bank (corporate records) ~2,200
Hyundai Capital (loan brokers) 146
KB Kookmin Bank 119
Hana Bank 89
BNK Busan Bank (contract staff) 11

The arithmetic: 40,300 + 25,729 + 146 + 119 + 89 + 11 = 66,394 individuals, and adding Welcome Savings Bank’s 2,200 corporate records gives 68,594. That matches the official “more than 68,000”. Two lenders, Yegaram and Shinhan, account for more than 99% of the individuals affected.

Side systems, not the vault

Every intrusion hit an internal system used by staff or partners, not the customer-facing banking apps. Shinhan’s leak came through a loan-progress inquiry service used by brokers; KB Kookmin’s through an employee mobile work-support system; Hana’s through a staff sales-support tool. “Security on customer-facing electronic financial services has been enormously strengthened, but internal employee-facing systems had been managed less rigorously,” the FSI official said.

Woori Bank and NH NongHyup Bank were also targeted but suffered no breach, because the specific weaknesses the attacker was looking for were not present. That detail matters more than any other in the story: the same AI-assisted attack failed against firms that had closed the basic gaps.

One operator, many targets

Reported detection times ranged from about 15 hours to nearly three days. CrowdStrike’s report concludes that “AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.” Adam Meyers, who leads counter-adversary operations at CrowdStrike, put it more bluntly on a press call reported by Reuters: it “allows one human to target many customers in a very short period of time using the power of AI”.

Who Is Behind the Attacks?

No one has been charged, and no government has named a culprit. What exists is a private-sector assessment, a set of personal details found in the exposed files, and a denial.

CrowdStrike’s moderate-confidence call

CrowdStrike has not attributed the activity to a known group. It says the operator is “likely a Chinese speaker and financially motivated”, and rates that judgement at moderate confidence. Its reasons are the use of a Chinese-developed tool, Chinese-language prompts, and session logs in which the operator asked Claude where Korean breach data is usually sold and for help finding Korean Telegram data-trading groups.

The attack traffic itself was spread across more than 20 IP addresses in over 10 countries, including the United States, Japan and Germany, according to the WSJ. Korean regulators have counted around 30 addresses across 12 countries and territories. Spreading traffic this way makes blocking and tracing slower.

The résumé in the logs

In one exposed session, the operator asked Claude to write a security-researcher résumé that listed the results of the ARTEX AI operations as achievements. The prompt included personal details. Reuters reports that they point to a 26-year-old in Guangdong province, China, although The Register notes the prompt gave conflicting age information.

CrowdStrike says the details “likely belong” to the attacker but that it “cannot definitively associate” them with the activity. We are not repeating them here. A Telegram account named in the report posted a denial on 8 October, and China’s foreign ministry said it was not familiar with the case and that China opposes hacking “as a matter of principle”. Anthropic and South Korean police did not respond to Reuters’ requests for comment.

Japan’s parallel wave

AFP reports that around 20 companies in Japan have said their data may have been compromised in a run of similar attacks, potentially affecting millions of customers. Japan’s police chief, Yoshinobu Kusunoki, said on Thursday it was “not clear what the background to these cases is or whether there are any links between them”. No one has publicly tied the Japanese incidents to ARTEX AI.

Does Pulling ARTEX AI Stop the Misuse?

artex ai chinese tool pulled misuse south korea hacks c christmas cracker pulled apart into two halves

Mostly, no. The developer’s decision is understandable and probably sensible for them personally, but its practical effect on attackers is small.

What closing the source does

Closing the source stops new releases and bug fixes. It removes the easiest place for a newcomer to find the code, and it ends the project’s public visibility on GitHub, which would have kept growing as the news spread. Ilya Kulyatin, CEO of Foundry Labs and founder of the Tokyo AI community, told AFP that open code lets users “remove restrictions built into the tool”, which “makes certain forms of misuse easier”.

What it cannot do

It cannot recall existing copies. ARTEX AI was public for about ten weeks. “Because the code was public, people could download it, change it and run it themselves,” Zhao said. “The developer could ask users to follow the rules, but had little control over their actions.” The FSI official was blunter still: “There are a great many open-source AI tools like ARTEX. There is currently no way to restrict everything being developed and distributed around the world.”

The defenders’ side of the argument

Openness cuts both ways. Kulyatin added that “openness also benefits defenders: researchers can inspect the code, identify weaknesses and improve protection.” Security teams have used open offensive tools for decades, and the debate about publishing them is as old as the tools themselves. The difference now is that an agent can chain the steps together with far less skill from the person running it, a point we explored in our report on CyberKimi weaponising a Chrome patch in under a day.

QuestionEffect of going closed-source
Can new users download the official code?No, the repository is gone
Do existing copies and forks stop working?No
Will the tool get new features or fixes?Not from the original developer
Can defenders still study the code?Harder, unless they already hold a copy
Are the models it calls affected?No, they remain available through their own services

Where the real control points sit

The agent was only one part of the chain. It needed models to think with, a way to pay for them, and servers to run from. CrowdStrike’s findings put attention on all three: the model providers, the API resellers that pass traffic through to them, and the hosting providers. That is where any lasting control will come from, alongside the model safety layers we examined in our piece on Abliteration.ai’s business of removing AI guardrails.

Some models are easier to misuse than others. The Herald Business reports that Palo Alto Networks’ Unit 42 described a Chinese-speaking actor in July who paired DeepSeek with an open-source agent and targeted more than 460 internet-connected systems, choosing DeepSeek because Western models proved too restrictive. With ARTEX AI, Claude Code was in the mix as well, and Anthropic has not commented.

What UK Law Says About Tools Like ARTEX AI

The ARTEX AI case raises a question that UK security teams and software developers face directly: when does publishing or using a hacking tool become a crime?

Section 3A of the Computer Misuse Act

The UK answer sits in section 3A of the Computer Misuse Act 1990. It makes it an offence to make, adapt or supply a tool “intending it to be used” to commit a computer misuse offence, and to supply one “believing that it is likely to be used” that way. The Act states that an “article” includes “any program or data held in electronic form”. The maximum penalty on indictment is two years in prison.

The test turns on intention and belief, not on the tool’s capabilities. A testing tool published for authorised use is not unlawful because it could be misused. That is why written statements of purpose, like the one Autumn-27 posted, matter: they speak to what the author intended. Developers releasing dual-use code in the UK should take legal advice on this point rather than relying on a licence notice.

What it means for teams using AI testing agents

For UK businesses, the practical risk runs the other way. An internal team or contractor running an AI testing agent against systems it is not authorised to test can commit an offence under section 1 of the same Act, whatever the tool’s intended purpose. An agent that wanders beyond its scope, for example by following links to a supplier’s portal, does not make that any less of a problem.

The National Cyber Security Centre’s penetration testing guidance already stresses clear scoping and written authorisation. Those controls matter more, not less, when the tester is software that acts quickly and does not stop to ask.

What UK Businesses Should Do Now About ARTEX AI

UK firms are not the targets named in this campaign, but ARTEX AI and tools like it are freely available, and the weaknesses they exploited are common. The lessons are practical, and most of them cost little. A broader view of the threat sits in the NCSC’s assessment of the impact of AI on the cyber threat to 2027.

Assume the tool is still in circulation

Treat the closed-source announcement as having no effect on your exposure. Copies remain in use, and other agents do the same job. Plan as though an attacker can run automated checks against every internet-facing system you own, quickly and cheaply. Good cybersecurity now means closing the gaps an agent would find in its first hour, because that is how long it may take.

Map every staff and partner-facing system

The Korean intrusions came through broker portals and staff support apps, not the main banking platforms. List every system your staff, brokers, contractors and suppliers can reach from the internet. A vulnerability assessment that only covers the flagship website would have missed every one of the systems that leaked here.

Watch for agent-speed behaviour

Automated attacks look different in logs: many lookups in a short time, systematic variation in requests, and fast switching between addresses when one is blocked. The FSI called IP blocking “little more than emergency first aid”. Set rate limits on lookup and search functions, alert on unusual query volumes, and make sure someone reviews those alerts out of hours. Current threat intelligence helps teams know which patterns to watch.

Govern your own use of AI testing agents

If your security team or suppliers use AI agents for testing, put rules around them and make those rules part of your IT governance, not an informal team habit. Treat ARTEX AI as the warning: a capable agent with no rules attached. The checklist below covers the basics.

ControlWhy it mattersOwner
Written scope and authorisation for every testKeeps testing lawful under the Computer Misuse ActSecurity lead
Approved list of agents and modelsStops unvetted code and unknown resellers handling your dataGovernance lead
Logs kept private and access-controlledThe ARTEX operator exposed their own sessions; yours hold your weaknessesSecurity operations
Hard limits on targets and ratePrevents an agent drifting into third-party systemsTester or supplier
Human sign-off before any exploit stepKeeps a person accountable for each actionEngagement manager

For external work, use an accredited supplier for penetration testing and ask directly which AI tools they use, where test data is processed and how scope is enforced.

Check your cyber insurance wording

A November 2025 Delinea survey of more than 750 security leaders, reported by Insurance Business, found that 42% said their cyber policies specifically exclude AI misuse or liability. Read your policy for AI-related exclusions and ask your broker how an AI-assisted intrusion would be treated.

Prepare for follow-on fraud

Korea’s regulators warned customers to expect phishing and loan scams using the leaked data. After any breach, the fraud that follows often does more harm than the leak itself. A tested incident response plan should include ready-made customer messages, a fraud reporting route and a decision on who speaks publicly.

ARTEX AI: Frequently Asked Questions

Is ARTEX AI still available?

Not from its developer. The GitHub repository was removed on 8 October and the project is now closed-source, with no further releases. Copies downloaded before that date still exist and can still be run, so the tool remains in circulation.

Did ARTEX AI hack the banks on its own?

No. Korea’s Financial Security Institute says a human attacker used the AI as a tool, and CrowdStrike’s evidence shows a person directing sessions, choosing targets and asking for help selling data. The agent sped up the work; it did not decide to do it.

Was Claude used in the attacks?

CrowdStrike found Claude Code session histories on the attacker’s server and says the operator used them alongside the ARTEX AI instance, which ran mainly on DeepSeek v4.1-flash. Anthropic has not commented publicly on the case.

Is the ARTEX AI developer accused of anything?

No authority has accused the developer of taking part in the attacks. The developer says the incident “has nothing to do with the tool’s author”, and the investigations so far point to a separate operator. Korean police are still investigating whether one person or a group was responsible.

Should UK firms block ARTEX AI?

You cannot reliably block a tool that anyone can copy and rename. Focus instead on the behaviour it produces and the gaps it looks for: unprotected staff and partner systems, weak authentication, missing rate limits and slow detection. Fixing those protects you against ARTEX AI and whatever replaces it.

References