ThinkFacility Sign in
  1. Home
  2. News

ARTEX's author takes the AI pentesting agent closed-source after CrowdStrike tied it to Korean bank breaches

The tool's author says the attack had nothing to do with them, and that ARTEX was built for research and authorized testing.

On October 8, 2026, the author of ARTEX said on their GitHub profile that the project won't be updated again and is going closed-source. There'll be no more public releases of any version, and no maintenance.

ARTEX is the agentic penetration-testing tool developed in China that CrowdStrike, a day earlier, tied to a run of breaches at South Korean financial organizations. When we checked on October 10, the ARTEX repository was gone from the author's public list of projects.

Tool
ARTEX, an open-source agentic penetration testing tool developed in China
Campaign
late September to early October 2026
Main LLM backend
DeepSeek v4.1-flash
Also used
GLM-5.3 (Zhipu AI) and Grok 4.6

What the author said

It's short. The author signs it only as the author of ARTEX (the GitHub handle is Autumn-27), and it's written in Chinese, so what follows is our translation.

It opens by saying the author has noticed ARTEX being misused by malicious actors to launch cyberattacks, and that the author had nothing to do with this attack. ARTEX was built for learning and research, it says, to help companies and organizations test security risks on assets they're authorized to test.

Misuse goes completely against that intent, and the author takes no responsibility for unauthorized or illegal use and strongly condemns it. Then the decision. Because the tool's been abused, ARTEX stops here. There's a last line telling users to keep to the law.

What CrowdStrike found

CrowdStrike's report, posted October 7, rests on open directories the attacker left exposed. They held Claude Code session histories, ARTEX configuration files and Claude memory files covering the campaign.

This activity demonstrates how AI tooling can enable a financially motivated threat actor to conduct multiple intrusions within a short time span.

From Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance

The company hasn't tied the attacks to a named group. It assesses, with moderate confidence, that the attacker is likely a Chinese speaker and financially motivated, based on the Chinese-developed tool and the Chinese-language prompts. In one session the attacker also asked Claude where Korean breach data usually gets sold.

One prompt asked Claude to write a security researcher's résumé listing the results of the ARTEX work, with a name, age and university attached. CrowdStrike says those details likely belong to the attacker but can't yet be tied to them for certain.

What closing the source changes

New versions, mostly. Closing a repository can't pull back copies people already downloaded, and the statement doesn't mention them. ARTEX also isn't a model of its own: in the Korean campaign it ran on DeepSeek, so whoever holds a copy still needs a model provider behind it.

The author's other projects, including the ScopeSentry scanning platform, are still public on the same GitHub profile.

More on this story