ARTEX developer closes project after reports of South Korean bank attacks

The developer of ARTEX, a tool for automated security testing, said the project would no longer be The announcement followed CrowdStrike’s report that the agent was used in cyberattacks on South Korean banks, though the link to the attacks remains the cybersecurity firm’s assessment.

Developer Autumn-27 said on GitHub that ARTEX would become closed-source and that no further public versions would be released. The developer said the project was originally built to help organizations test network security and opposed illegal use of the software.

CrowdStrike said a person suspected of attacks on South Korean financial institutions likely used ARTEX alongside Claude Code. That attribution is the cybersecurity company’s assessment. The Hindu, citing Reuters, also reported that the project’s GitHub page had been removed.

ARTEX was released on GitHub this year as an agent designed to automate penetration testing. It is not a standalone language model and can connect to external models, including ChatGPT, Claude and DeepSeek.

At least nine South Korean banks had disclosed or been reported by local media as targets of cyberattacks since late September. Police opened an investigation, and President Lee Jae Myung called for a strong response. Chinese Foreign Ministry spokesperson Mao Ning said the ministry was not familiar with the case and reiterated that China opposes hacking.