The Chinese developer responsible for ARTEX, an artificial intelligence agent used in security testing, announced on Thursday (8) that it will end updates and support for the tool, in addition to converting the project to closed source. The decision came after a CrowdStrike investigation linked the software to attacks against financial institutions in South Korea, carried out between late September and early October.

The creator, identified on GitHub as Autumn-27, said that he will not make new public versions of ARTEX available. The original repository was also removed from the platform, according to a Reuters check. The move interrupts the official distribution of new open versions, but does not guarantee that copies already made available will stop working.

Developed to automate penetration tests and identify vulnerabilities, ARTEX connects external language models to security tools. Its creator said the original goal was to help companies assess risks and condemned any illegal use of the software. He did not assume responsibility for the attacks under investigation.

Investigation identifies DeepSeek and GLM in the agent's operation

A report published by CrowdStrike on October 7 identified the digital infrastructure used in the campaign against South Korean financial institutions. The researchers located session histories from Claude Code, ARTEX configuration files, and Chinese-language instructions stored in directories accessible on the internet.

The analysis revealed an operation distributed between two servers. One of them, located in Hong Kong, concentrated the main infrastructure of the operator under investigation. The second hosted an ARTEX instance considered likely responsible for the activities described against the financial institutions.

That instance used DeepSeek v4.1-flash as the main model, while additional Claude Code sessions used GLM-5.3, from Zhipu AI, and Grok 4.6. The records show how different artificial intelligence models were incorporated into the suspect's operational environment, without demonstrating that the companies responsible for those models participated in the attacks.

CrowdStrike also found evidence of queries about places to sell stolen data. The company assesses, with moderate confidence, that the person responsible probably speaks Chinese and has a financial motivation, but did not establish his identity conclusively.

Among the compromised systems reported are a loan inquiry service used by financial intermediaries and a mobile platform supporting the work of bank employees.

At least nine South Korean banks have been mentioned in reports of attacks since late September, but the total number of institutions actually compromised remains unconfirmed. There is also no evidence that all the incidents used ARTEX.

The incidents led South Korean police to open an investigation and President Lee Jae Myung to demand protection measures. While authorities investigate the extent of the leaks, the shutdown of public development of ARTEX constitutes the first concrete change announced by the tool's creator after the investigations were disclosed.

Tools mentioned

More from Radar