Full Breakdown
Artex AI Pen-Testing Tool Shut Down After South Korean Bank Breaches
By Drooid · · How we work
Core Event: Conversion of Artex to Closed Source
In early October 2026 the Chinese developer of the AI-driven penetration-testing tool Artex announced that the project would be converted to a closed-source model and would no longer receive public updates or maintenance support. The decision follows cybersecurity investigations that linked the open-source tool to a campaign targeting at least nine South Korean financial institutions from late September to early October 2026.
Background & Context: Intended Purpose and Release
Artex was released on GitHub on July 26, 2026 as an agentic AI framework designed to automate security-risk testing for enterprises. The tool does not contain its own large language model; instead it connects to external models such as Anthropic’s Claude, OpenAI’s ChatGPT, and China-based DeepSeek.
Data & Statistics: Scope of the Breaches
- 68,000 individuals were reported as affected by the attacks, according to South Korean authorities.
- Shinhan Bank disclosed data on roughly 25,000 customers; Yegaram Savings Bank reported about 40,000 affected accounts.
- Other banks, including KB Kookmin and Hana, reported smaller leaks (119 and 89 customers respectively).
- The campaign exploited services such as a loan-progress inquiry portal and an employee mobile work-support system rather than core banking platforms.
Official Statements & Responses
- Lee Jae Myung, President of South Korea, called for “robust response measures” after multiple banks reported breaches in late September.
- CrowdStrike assessed with moderate confidence that the attacker was a Chinese-speaking individual, likely 26 years old, who used Artex together with Anthropic’s Claude and other large language models.
Conflicting Reports & Gaps
- Sources differ on the exact number of financial institutions compromised. Reuters and multiple Korean media outlets cite “at least nine” banks, while other reports list only five specific lenders (Shinhan, KB Kookmin, Hana, Yegaram Savings, BNK Busan).
- The total count of affected organisations remains unconfirmed; some analyses note overlapping IP addresses but cannot verify whether additional, smaller lenders were involved.
- Personal details extracted from Claude session logs (e.g., a Telegram handle @YY520CN) are believed to belong to the attacker, but CrowdStrike and other analysts state they cannot definitively link the individual to the campaign.
Verbatim Quotes
- “This assessment is made with moderate confidence based on the use of the Chinese-developed tool ARTEX and observed Chinese-language prompts,” — China. CrowdStrike
- “In addition to conducting ARTEX-related operations, the threat actor asked Claude where threat actors typically sell Korean data breach information and asked Claude for assistance in finding Korean Telegram data sales groups,” — China. CrowdStrike
- “Model reasoning is expensive and slow,” — ZenoX
- “The use of agentic AI tooling alongside traditional offensive capabilities highlights the continued evolution observed by CrowdStrike in adversarial tradecraft,” — Ashley Campion, analyst
Why It Matters
The Artex episode illustrates how open-source AI tools, originally intended for defensive security testing, can be repurposed for offensive operations. By integrating multiple large language models, the attacker accelerated reconnaissance, vulnerability research, and exploitation steps that traditionally require extensive manual effort.
