ARTEX Developer Closes AI Pentest Tool After Korea Bank Hacks
TL;DR
- CrowdStrike attributes late-September intrusions at Shinhan Bank and Yegaram Savings Bank to an operator running the Chinese open-source ARTEX pentest agent.
- ARTEX developer Autumn-27 converted the GitHub project to closed source on October 8, saying the misuse had nothing to do with them.
- The tool runs DeepSeek v4.1-flash with Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6, reached via a reseller at xcai[.]pro.
CrowdStrike has traced a late-September string of intrusions at Shinhan Bank, Yegaram Savings Bank and other South Korean financial firms to an operator running ARTEX, an open-source agentic penetration-testing tool built in China. Its developer, who goes by Autumn-27 on GitHub, responded on October 8 by converting the project to closed source and halting further releases.
"The ARTEX project will no longer be updated and will be converted to a closed source. There will be no release of any version or maintenance support in the future," Autumn-27 wrote. The developer said ARTEX "was originally designed for the purpose of learning and research" and that the attacks "had nothing to do with them."
ARTEX runs DeepSeek v4.1-flash as its primary backend, with Z.ai's GLM-5.3 and SpaceXAI's Grok 4.6 as supplementary models, and the operator reportedly reached those APIs through a reseller at xcai[.]pro, The Hacker News reports. CrowdStrike Intelligence identified two servers behind the campaign: a Hong Kong IP that hosted the backbone, and a second machine at 38.244.50[.]120 running the ARTEX instance. Investigators found exposed Claude Code session histories, Claude memory files and ARTEX configuration files on the Hong Kong server.
Those Claude artifacts also surface the operator's downstream plans. CrowdStrike reports that "the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups," with the Telegram handle "@YY520CN" referenced in the prompts. The actor is suspected to be Chinese-speaking and financially motivated and is not currently tied to any tracked group. It's the latest AI-weaponization alert on our cybersecurity tracker, where Japan's SoftBank and Daiwa breach disclosures landed earlier the same week.
South Korea's Financial Services Commission and Financial Supervisory Service issued a public warning telling consumers to "exercise vigilance and be on the lookout for potential phishing attacks and loan scams stemming from leaked data."
Originally reported by thehackernews.com
Read the original article →Original headline: ARTEX Developer Takes AI Pentest Tool Closed-Source After Attribution to South Korean Bank Hacks