Evidence Suggests ARTEX Used in Attacks on 7 Financial Firms... Developer: "No Further Updates"

The Chinese-made artificial intelligence (AI) penetration-testing tool ARTEX, reportedly used in a series of hacking attacks targeting South Korean financial institutions, will no longer be developed publicly. ARTEX has faced controversy over its alleged misuse in cyberattacks.


According to AFP and other foreign media outlets on October 10, ARTEX developer Autumn-27 said in a post uploaded to the developer platform GitHub on October 8 that “ARTEX has been misused” and that “in light of the tool’s misuse, ARTEX will no longer be updated and will transition to closed-source development.” The developer added, “No further versions will be made available to the public, and no maintenance support will be provided.”

ATMs at domestic banks

ATMs at domestic banks

View original image

The ARTEX team said using the tool for cyberattacks goes against the developer’s intentions, but did not directly mention the hacking incidents in South Korea. The team also said it would not be responsible for actions that violate laws and regulations through the use of the tool. The ARTEX-related page has reportedly also disappeared from GitHub.


Experts noted that switching ARTEX to closed-source development could make it more difficult for new users to create code. However, because programs that have already been distributed cannot be recalled, halting development alone is unlikely to prevent cyberattacks using ARTEX.


“This decision by ARTEX will not be able to remove copies that have already been downloaded or prevent users from continuing to use them,” a Chinese information and communications technology expert told AFP.


ARTEX is an autonomous penetration-testing program designed to connect large language models (LLMs) so that AI agents can analyze targets, plan intrusion routes, and run security tools. On October 7, U.S. cybersecurity firm CrowdStrike said attacks targeting South Korean financial institutions had taken place between late September and early October. Its analysis of servers used in the hacks found that the attackers had used ARTEX alongside LLMs.



The hacking incidents came to light after breaches affected seven financial companies: Shinhan Bank, KB Kookmin Bank, Hana Bank, BNK Busan Bank, Yegaram Savings Bank, Welcome Savings Bank, and Hyundai Capital. The IP addresses used in attacks on commercial banks, savings banks, and capital companies differed, but evidence suggested that the same attacker had targeted multiple financial firms using similar methods while changing IP addresses. CrowdStrike said the attacker may be a 26-year-old living in Guangdong Province, China. However, it stressed that this was an inference based on circumstantial evidence and did not constitute a definitive identification.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing