ARTEX Developer Closes Source After South Korean Bank Attacks
Developer Autumn-27 converted the ARTEX AI penetration tool to closed-source after it was used in cyberattacks against nine South Korean banks.
The developer of Autumn-27, an open-source AI agent designed for automated penetration testing called ARTEX, converted the project to closed-source and ceased all public updates. This decision followed reports that the tool was utilized in a series of cyberattacks targeting at least nine South Korean banks since late September.
CrowdStrike identified that a suspect, believed to be a 26-year-old based in China, used ARTEX in conjunction with Anthropic's Claude Code to attempt to steal customer personal data. In response to the breach, South Korean police launched a probe and President Lee Jae Myung called for robust response measures.
Autumn-27 stated the tool was intended for security risk testing and opposed its illegal use, noting that no further versions or maintenance support would be provided to the public. The Ministry of Foreign Affairs of the People's Republic of China stated it was unfamiliar with the specific case but maintained that China opposes hacking activities.