ARTEX AI agent goes closed-source after being linked to South Korean bank hacks

2 hours ago 3



An open-source AI agent designed for penetration testing has been pulled from public access after cybersecurity researchers linked it to a string of cyberattacks on South Korean banks. The tool’s Chinese developer made ARTEX closed-source on October 8, 2026, the same day its GitHub page was taken down. The attacks, which struck between late September and early October 2026, breached internal systems at between seven and nine South Korean financial firms. Approximately 68,000 individuals had personal data exposed, including names, phone numbers, annual incomes, and loan limits. Shinhan Bank bore the worst of it, with around 25,000 customer records compromised. What ARTEX is and how it was allegedly used ARTEX was built as an autonomous AI agent for authorized security testing. The developer behind the project, identified by the GitHub handle Autumn-27 and named as Chinese cybersecurity engineer Li Puhua, created it as an open-source resource for the security community. CrowdStrike, one of the cybersecurity firms that investigated the incidents, tied the cyber operations to a financially motivated individual in China. The firm estimates the operator to be a 26-year-old based in the c...

Read Entire Article