News

ARTEX's Developer Pulled the AI Hacking Agent After a Suspect Paired It With Claude Code to Hit Korean Banks

The Chinese developer of ARTEX, an open-source AI penetration testing agent, took it closed source a day after CrowdStrike tied it to breaches at South Korean banks, where the attacker's own AI chat logs were left exposed.

ARTEX's Developer Pulled the AI Hacking Agent After a Suspect Paired It With Claude Code to Hit Korean Banks

An open-source AI agent built to help companies find holes in their own networks ended up inside a run of attacks on South Korean banks. Now the developer behind it has pulled the code from public view and washed their hands of what happened.

On Thursday, the developer known on GitHub as "Autumn-27" posted that ARTEX would go closed source. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided," the post said, according to Reuters. The project's GitHub page has since been taken down.

The timing was not subtle. A day earlier, CrowdStrike had published a report tying ARTEX to the breaches.

A tool for defenders, used for a heist

ARTEX appeared on GitHub this year as an agent that automates penetration testing, the work of probing systems the way an attacker would. It is not a language model on its own. It plugs into outside models such as ChatGPT, Claude and DeepSeek to do the thinking.

The developer said the original goal was to help enterprises and organizations run security risk tests and improve their defenses. Without mentioning the Korean attacks directly, they said they opposed any illegal use and bore no responsibility for conduct that breaks laws and regulations.

The damage is real. At least nine South Korean banks have disclosed attacks or been reported as targets since late September, among them Hana Bank, KB Kookmin Bank and Shinhan Bank, Yonhap reported. Police opened a probe this week, and President Lee Jae Myung called for a robust response. The breaches came fast, with seven banks and lenders hit in a single week before investigators spotted ARTEX traces.

The attacker's chat logs gave the game away

What makes this case unusual is how much the attacker left lying around. CrowdStrike found attacker-controlled open directories sitting exposed, holding Claude Code session histories, ARTEX configuration files and Claude memory files. One server hosted an ARTEX instance next to a CLAUDE.md file with a Chinese-language pentesting prompt. A Hong Kong-based IP address served as the main infrastructure.

The campaign ran from late September to early October and ended with data stolen from South Korean financial organizations. According to Yonhap, the attacker mostly ran DeepSeek v4.1-flash, topped up with GLM-5.3 and Grok 4.6, all driven through Claude Code sessions.

The logs read like a criminal's search history. The attacker asked Claude where threat actors usually sell Korean breach data and for help finding Korean Telegram groups that trade it, Channel NewsAsia reported.

In another session, the same person asked Claude to write a security researcher resume. It listed a Telegram handle, an age of 26, an education background and a location in Maoming, in China's Guangdong province. CrowdStrike said those details likely belong to the attacker, but cautioned that it could not definitively identify them.

Not a state group, and not a robot

CrowdStrike stopped short of naming a culprit. "While this activity has not been attributed to a named adversary, the threat actor is likely a Chinese speaker and financially motivated," the company wrote, a call it made with moderate confidence based on the Chinese-developed tool and the Chinese-language prompts.

Nobody here should read the story as AI robbing banks on its own. A person picked the targets, wired the models together, steered the sessions and went looking for buyers. The AI did the legwork, and then kept a detailed diary of the whole job.

Beijing has kept its distance. Foreign ministry spokesperson Mao Ning said Thursday the ministry was not familiar with the case and that China consistently opposes and combats hacking.

That leaves an awkward picture. An agent released for defenders helped pull customer data out of Korean banks, the attacker was undone by their own AI transcripts, and the developer's response was to lock the code away and say the damage was someone else's problem. Anyone who already downloaded ARTEX still has it.

Some offers on this page may be paid placements or contain affiliate links.

Subscribe to Techpresso

Free daily newsletter, read in 5 minutes.

Subscribe free