ARTEX Developer Pulls AI Security Tool After Links To Bank Hacks

The developer announced the decision on Thursday, October 8. Reuters reported the withdrawal on Friday and confirmed that the project’s GitHub page had been taken down.

Latest News
  • ARTEX’s developer has ended public releases and maintenance.

  • CrowdStrike linked the tool to attacks on South Korean financial institutions.

  • Investigators found AI session records and configuration files on attacker-controlled servers.

  • The findings describe human-directed attacks assisted by AI, with the suspect’s identity still unconfirmed.

October 09, (THEWILL) – The developer of ARTEX, an artificial-intelligence tool built for security testing, has withdrawn public access after researchers linked it to cyberattacks against South Korean financial institutions.

Operating under the GitHub name Autumn-27, the developer announced the decision on Thursday, October 8. Reuters reported the withdrawal on Friday and confirmed that the project’s GitHub page had been taken down.

“No further versions will be released to the public nor will maintenance support be provided”, the developer said, citing misuse.

Ask ZiVA 728x90 Ads

What Researchers Found

Close-up of a laptop screen displaying colorful code in a editor, with a blurred office background.
Programming code displayed on a laptop Source Christina Morillo Pexels

In its October 7 investigation, cybersecurity company CrowdStrike said it found ARTEX configuration files and records of Claude Code sessions on infrastructure associated with the attacks. Those records indicated activity against South Korean financial organisations between late September and early October.

ARTEX belongs to a category of software used for penetration testing, in which security teams probe systems for weaknesses. Such testing requires permission from the system’s owner. The same capabilities can also be directed at systems without authorisation.

CrowdStrike’s findings describe an attacker using AI tools alongside conventional hacking methods. They do not establish that an AI system independently selected the victims or decided to steal their information.

The company also found requests for help locating markets for stolen Korean data. However, it cautioned that personal details discovered in a separate AI session could not be definitively tied to the attacker.

At least nine South Korean banks had disclosed or been reported as targets since late September, according to Reuters. South Korean police opened an investigation.

Adam Meyers, CrowdStrike’s senior vice-president of counter adversary operations, said the technology “allows one human to target many customers in a very short period of time”.

READ ALSO:

Banking Security Beyond the Customer App

Front view of a modern brick office building with large blue-tinted windows and a row of tall evergreen trees in front against a clear blue sky.
CrowdStrikes office in Sunnyvale California Source Coolcaesar Wikimedia Commons

For Nigerian banks and fintech companies, the investigation offers a specific area for scrutiny beyond their main websites and customer-facing apps.

CrowdStrike cited industry accounts of intrusions involving a loan-progress inquiry service used by financial brokers and an employee mobile work-support system. It did not independently confirm every reported breach, and its report left the total number of affected organisations unresolved.

Those examples suggest that a bank’s security review needs to cover the smaller systems through which staff and intermediaries access information. A customer may never use such a service directly, although it could still hold their personal details.

Nothing in the reports reviewed establishes that Nigerian institutions were targeted in this campaign. Nor does the withdrawal establish that previously downloaded copies of ARTEX have stopped working.

The developer said the software was intended to help organisations assess security risks and opposed illegal use. The statement did not specifically address the South Korean attacks.

CrowdStrike has published technical indicators associated with the campaign, giving security teams information they can check against their own network records while the investigation continues.

Illustrated portrait of a smiling Black woman with short dark hair (head-and-shoulders).

Joy Onuorah is a business journalist and brand communications specialist covering financial markets, artificial intelligence, digital economy, and the ideas reshaping business across Africa and the global market. Beyond her reporting for TheWill, Joy uses brand strategy, storytelling, copywriting, and high-value SEO to help brands build lasting market authority.

More Articles Like This