SharpPostTechnology

The developer of ARTEX, a China-developed open-source tool for AI-assisted penetration testing, said on October 8 that the project would stop releasing public updates and become closed-source, after cybersecurity firm CrowdStrike linked it to attacks on South Korean financial institutions.

The developer, who uses the handle Autumn-27, said in a GitHub statement that ARTEX was intended for research and authorised security testing. The developer denied taking part in malicious attacks, condemned unauthorised use and said no further public releases or maintenance support would be provided.

CrowdStrike published its findings on October 7, saying attackers had used ARTEX and large language models in intrusions from late September into early October and had stolen data. Researchers found Claude Code session histories, ARTEX configurations and Claude memory files in a publicly accessible directory on an attacker-controlled server. Chinese-language prompts and a server in Hong Kong helped them reconstruct the operation, according to the investigation.

The ARTEX instance mainly called DeepSeek v4.1-flash, while other Claude Code sessions used GLM-5.3 and Grok 4.6, the report said. An operator also asked Claude where to sell leaked South Korean data. The records showed people configuring tools, choosing models and looking for buyers.

ARTEX is not itself a large language model. It connects models to security-testing tools, allowing a model to help plan tasks and process tool results. Penetration testing normally involves probing for weaknesses within an agreed scope and with the owner's permission; the same capabilities can be used to break into systems without authorisation.

An accessible fork maintained by RuoJi6 lists features for task sessions, tool calls, model configuration and human approval. Such software lets models participate in a continuing testing workflow rather than simply answer technical questions, reducing some manual work. Those features do not establish who performed each step in this case, and CrowdStrike's public report does not document an entire attack conducted without human intervention.

ARTEX dashboard showing tasks, model usage, tool activity and findings.
ARTEX dashboard illustration; not a screenshot of the attacks described in this report. Source: RuoJi6/ARTEX repository(AGPL-3.0)。

Reuters reported on October 9 that at least nine South Korean banks had disclosed attacks or been identified by local media as targets since late September, and that police were investigating. That tally does not mean ARTEX was confirmed to have breached all nine banks.

CrowdStrike assessed with moderate confidence that the operators were likely Chinese-speaking and financially motivated. It had not attributed them to a named threat group, and clues to individual identities remained unconfirmed. The public investigation did not establish Chinese government involvement.

The risk to banks also depends on what systems the tools can reach. Where a model can repeatedly call tools against vulnerable systems, attackers may be able to make more attempts with less manual work. The available evidence raises concerns about that efficiency gain but does not quantify an increase in ARTEX's success rate or establish that AI alone caused the data theft.

South Korea's Financial Services Commission said in an October 6 statement that existing rules require vulnerability checks at least once a year for general information-processing systems and twice a year for public websites. Authorities were preparing measures to shorten inspection cycles, widen coverage and strengthen remediation, with an announcement planned soon.

The original developer's withdrawal has not removed all publicly available code. When SharpPost checked GitHub on October 9, the RuoJi6 fork remained accessible. Its page said it retained the original commit history and AGPL-3.0 licence and independently built and released the software.