{"slug": "chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack", "title": "Chinese Developer Closes ARTEX AI Agent After South Korean Bank Hack", "summary": "Chinese developer \"Autumn-27\" removed the open-source ARTEX AI penetration-testing agent from GitHub on Thursday and said it will be converted to closed source with no further updates or maintenance support, after a CrowdStrike report linked ARTEX and Anthropic's Claude Code to intrusions at South Korean banks. At least nine banks have disclosed or been reported as targets since late September, prompting a South Korean police investigation and a call from President Lee Jae Myung for countermeasures; CrowdStrike attributed the attacks to a China-based 26-year-old suspect. Anthropic has not publicly commented, and Chinese foreign ministry spokesperson Mao Ning said the ministry was not familiar with the case and that China opposes hacking activities.", "body_md": "**October 9, 2026, (Inside AI) —** The Chinese developer behind an open-source AI penetration testing tool has pulled the project from public access after cybersecurity investigators linked it to a series of intrusions at South Korean banks. The developer, operating under the GitHub handle **\"Autumn-27\"**, announced on Thursday that **ARTEX** would be converted to a closed-source project and receive no further updates or maintenance support.\n\nThe decision followed a report from U.S. cybersecurity firm **CrowdStrike**, which identified the ARTEX agent and Anthropic's **Claude Code** as tools used in attacks targeting customer data at South Korean financial institutions. At least **nine banks** have disclosed or been reported as targets since late September, triggering a police investigation and a call from President **Lee Jae Myung** for robust countermeasures.\n\nARTEX, released on GitHub earlier this year, is not a standalone large language model. It connects to external LLMs such as ChatGPT, Claude, and DeepSeek to automate penetration testing, helping organizations probe their networks for vulnerabilities. The developer said the tool was intended for legitimate security risk testing and that they opposed any illegal use.\n\n**\"Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to open source. No further versions will be released to the public nor will maintenance support be provided,\"** the developer wrote on GitHub before the page was taken down.\n\nThe developer did not explicitly address the [South Korean bank attacks](https://insideai.news/news/cybersecurity-ai/ai-bank-hacks-south-korea/13639/) but stated they bore no responsibility for conduct that violates laws and regulations. The GitHub repository is no longer accessible, according to checks by Inside AI.\n\n[CrowdStrike attributed the attacks](https://insideai.news/news/cybersecurity-ai/ai-tools-south-korean-bank-hacks/13820/) to a China-based **26-year-old** suspect. The firm's report, released Wednesday, said the individual used ARTEX in combination with Claude Code to automate parts of the intrusion process. The involvement of a commercial AI coding assistant in a cyberattack highlights a growing challenge for AI developers: preventing their tools from being repurposed for malicious ends.\n\nAnthropic, the maker of Claude Code, has not publicly commented on the CrowdStrike report. The company's usage policies prohibit using its models for unauthorized access to systems or data. However, enforcing those rules in real time remains difficult, especially when AI agents operate through third-party frameworks like ARTEX.\n\nChinese foreign ministry spokesperson **Mao Ning** told a regular press briefing on Thursday that the ministry was not familiar with the case, adding that China consistently opposes and combats hacking activities.\n\nThe South Korean police probe is ongoing. The attacks have raised concerns about the security of financial data in one of Asia's most digitally connected economies. Banks in South Korea have invested heavily in cybersecurity, but the use of AI agents to automate vulnerability discovery and exploitation may be outpacing traditional defenses.\n\nARTEX is one of several open-source AI agents designed for security testing that have emerged in the past year. These tools lower the barrier to entry for penetration testing, but they also create new risks when they fall into the wrong hands. The developer's decision to close the project reflects a broader dilemma: how to balance open collaboration with misuse prevention.\n\nThe incident also draws attention to the role of large language models in cyberattacks. Claude Code, ChatGPT, and similar tools are built to assist with coding and problem-solving. When connected to an agent like ARTEX, they can generate scripts, suggest attack vectors, and automate repetitive tasks. This dual-use nature is a central tension in AI safety research.\n\nFor now, the ARTEX repository is gone, and its developer has stepped back. The South Korean banks are still assessing the damage. The suspect remains at large, and the investigation continues. The case may become a reference point for how AI agents are governed and how quickly developers respond when their creations are weaponized.", "url": "https://wpnews.pro/news/chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack", "canonical_source": "https://insideai.news/news/cybersecurity-ai/artex-ai-agent-closed-source/13924/", "published_at": "2026-10-09 03:17:50+00:00", "updated_at": "2026-10-09 03:47:13.837408+00:00", "lang": "en", "topics": ["ai-agents", "ai-safety", "ai-tools", "artificial-intelligence"], "entities": ["Autumn-27", "ARTEX", "CrowdStrike", "Anthropic", "Claude Code", "Lee Jae Myung", "Mao Ning", "GitHub"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack", "markdown": "https://wpnews.pro/news/chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack.md", "text": "https://wpnews.pro/news/chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack.txt", "jsonld": "https://wpnews.pro/news/chinese-developer-closes-artex-ai-agent-after-south-korean-bank-hack.jsonld"}}