The developer of ARTEX, an open-source artificial intelligence (AI) hacking agent, has removed the project from GitHub and made it closed source after cybersecurity researchers linked the tool to attacks targeting South Korean banks.
ARTEX was built to automate penetration testing, a process in which security professionals test computer systems for weaknesses. The tool can connect to AI models, including ChatGPT, Claude and DeepSeek, to help carry out security testing tasks.
However, the tool has come under scrutiny after researchers linked its use to a cyber campaign involving South Korean financial institutions. According to Reuters, CrowdStrike said a suspected 26-year-old attacker based in China used ARTEX alongside Claude Code during the campaign.
Reuters also reported that nine South Korean banks were among the institutions investigating attacks. The incident has raised concerns about how open-source AI tools built for legitimate security work can also be used in cyberattacks.
What Is ARTEX and How Does the AI Hacking Agent Work?
ARTEX is an AI agent developed to automate parts of penetration testing. Security researchers and ethical hackers use penetration testing to identify weaknesses in computer networks, applications and other systems before malicious attackers can exploit them.
Unlike traditional security tools that rely heavily on predefined commands, AI agents can use language models to help plan tasks, interpret results and decide what to do next. This can reduce the amount of manual work required during certain security assessments.
ARTEX can connect to several AI models, including ChatGPT, Claude and DeepSeek. This allows users to use different models while working through security-testing tasks. Tools like ARTEX can have legitimate uses. Security teams can use automation to identify vulnerabilities, test their defences and investigate potential weaknesses more efficiently.
However, similar capabilities can also help malicious actors automate parts of an attack. The distinction depends on how the tool is used, which systems it targets and whether the person operating it has permission to conduct the testing.
ALSO READ: OpenAI Faces Questions After Three Researchers Dispute Misconduct Claims
ARTEX’s Shift to Closed Source Raises Questions About AI Cybersecurity
ARTEX’s developer removed the project from GitHub and switched it to a closed-source model after researchers linked the tool to attacks targeting South Korean banks.
Open-source software allows people to inspect, download, modify and redistribute source code under its licence. This makes it easier for developers and security professionals to examine how a tool works, improve it and adapt it for different needs.
However, public access can also make it easier for malicious users to obtain and modify software without the original developer’s involvement.
By making ARTEX closed source, its developer has restricted public access to the project’s code. The change may make it harder for new users to obtain the tool directly from its original repository, although it does not guarantee that existing copies have disappeared or that the software can no longer be used.
The move also highlights a difficult question for developers of open-source security tools: how can they support legitimate cybersecurity research while limiting the risk of their software being misused? Closing a project can reduce access through official channels, but it cannot automatically prevent people who already have copies from continuing to use them.
CrowdStrike Links ARTEX Files to Attacks on South Korean Banks
Cybersecurity company CrowdStrike published its findings on October 7, 2026, after investigating activity linked to attacks against South Korean financial organisations. Its analysis identified ARTEX configuration files, Claude Code session histories and other files associated with the suspected attacker.
The company said the campaign ran from late September to early October. The attacker reportedly used ARTEX alongside large language models to target financial organisations and obtain data from compromised systems.
CrowdStrike assessed that the suspected attacker was likely a Chinese speaker and financially motivated. However, it did not attribute the activity to a named threat group, and the identity of the person responsible has not been independently confirmed.
Reuters reported that at least nine South Korean banks had been targeted or were investigating attacks. South Korean authorities have also launched an investigation into the incidents. This shows how AI tools can be combined with existing hacking techniques to help attackers carry out operations against multiple organisations.
How AI Agents Could Help Hackers and Security Teams
AI agents can perform multiple connected tasks with less direct human involvement than traditional software. In cybersecurity, this may include examining systems, identifying possible vulnerabilities and helping users interpret technical findings.
These abilities can benefit defenders. Security teams can use AI agents to check their systems more quickly, investigate suspicious activity and identify weaknesses that need attention. However, the same automation can create risks when attackers use it without permission.
Tasks that previously required considerable manual effort may become easier to carry out, particularly when AI agents can connect to different language models and security tools. The ARTEX case also highlights the challenges of monitoring AI-assisted cyberattacks.
Researchers may need to examine not just the software used in an attack, but also the AI tools, configuration files and digital infrastructure connected to it. Still, the incident does not establish that AI agents can independently carry out every stage of a sophisticated cyberattack. Human decisions, conventional hacking techniques and the security weaknesses of targeted systems can remain important parts of these operations.
What ARTEX’s Shutdown Means for the Future of Open-Source AI Security
ARTEX’s move to closed source is a direct response to concerns about misuse. Its developer said the project would no longer receive updates or maintenance support, and no further versions would be released publicly. Reuters also confirmed that the project’s GitHub page had been taken down.
The decision may limit access for people who have not already obtained the software. However, closing the original repository cannot guarantee that existing copies will disappear or that similar tools will not emerge.
For developers, the case raises questions about how to distribute security software responsibly. Open-source projects allow researchers to review code, find bugs and improve security tools. At the same time, public access can make it easier for malicious users to adapt those tools for unauthorised activity.
Financial institutions may also need to review how they protect customer information, secure systems used by employees and third-party partners, and detect unusual activity across their networks.
The main concern is not simply that ARTEX was open source, but that an AI agent intended for security testing was reportedly used in attacks against financial organisations. As AI agents become more capable, developers and organisations will face growing pressure to make legitimate security work easier without giving attackers an unnecessary advantage.





