Chinese Developer Makes ARTEX AI Agent Closed-Source After Cyberattack Allegations
A Chinese developer has converted the open-source AI agent ARTEX into a closed-source project after cybersecurity firms alleged it was used in a recent cyberattack campaign targeting South Korean banks. The developer cited misuse as the reason for discontinuing updates and maintenance, while US cybersecurity firm Crowdstrike identified a China-based suspect linked to the attacks.
Editor, Lazyfounder

30 SEC SUMMARY
- A Chinese developer has converted the open-source AI agent ARTEX into a closed-source project after cybersecurity firms linked it to cyberattacks on South Korean banks.
- ARTEX, designed for penetration testing, was allegedly used by a China-based suspect in recent cyberattacks targeting at least nine South Korean banks.
- The developer stated the tool will no longer be updated or maintained due to its misuse, and its GitHub page has been taken down.
- US cybersecurity firm Crowdstrike identified a 26-year-old China-based suspect as the likely perpetrator, who also used Anthropic’s Claude Code.
- South Korean President Lee Jae Myung has called for robust response measures, while China’s foreign ministry denies involvement.
TABLE OF CONTENTS
KEY HIGHLIGHTS
- ARTEX, an open-source AI agent for penetration testing, has been made closed-source by its Chinese developer following allegations of its use in cyberattacks on South Korean banks.
- The developer, known as 'Autumn-27' on GitHub, announced the tool will no longer be updated or maintained due to its misuse.
- Crowdstrike identified a 26-year-old China-based suspect as the likely perpetrator behind the attacks, who allegedly used ARTEX alongside Anthropic’s Claude Code.
- At least nine South Korean banks have reported cyberattacks since late September, prompting a police investigation and a call for stronger response measures by President Lee Jae Myung.
- The Chinese foreign ministry stated it was not familiar with the case but opposes and combats hacking activities.
ARTEX’s shift from open-source to closed-source
The Chinese developer behind ARTEX, known by the GitHub handle 'Autumn-27,' announced the tool will no longer be updated or maintained as an open-source project. According to Mint, the decision follows allegations that ARTEX was used in cyberattacks targeting at least nine South Korean banks since late September.
ARTEX was originally designed to help enterprises and organizations conduct penetration testing and improve their cybersecurity defenses. However, its GitHub page has since been taken down, and the developer stated they oppose any illegal use of the software and will not be held responsible for conduct violating laws or regulations.
Cyberattacks on South Korean banks and alleged perpetrator
US cybersecurity firm Crowdstrike reported that the suspect behind the cyberattacks on South Korean banks is likely a 26-year-old based in China. According to their findings, the suspect used ARTEX alongside Anthropic’s Claude Code to allegedly steal customers’ personal data.
The attacks, which have targeted at least nine banks, prompted a police investigation in South Korea. President Lee Jae Myung has called for robust response measures to address the cyber threats.
While ARTEX’s developer denied responsibility for its misuse, the incident has drawn attention to the risks of open-source tools being repurposed for malicious activities.
China’s response to the allegations
The Chinese foreign ministry, represented by spokesperson Mao Ning, stated it was not familiar with the details of the case but emphasized that China consistently opposes and combats hacking activities. The ministry did not address the specific allegations involving ARTEX or the suspected individual.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
This incident highlights the dual-use risks of open-source AI tools, particularly those designed for cybersecurity. While tools like ARTEX can help organizations identify vulnerabilities, their accessibility also makes them attractive to malicious actors. For founders and operators, this underscores the importance of proactive governance—whether in vetting how open-source tools are used internally or anticipating potential reputational and legal risks if their own products are misused.
The move to close ARTEX also reflects a growing tension in the AI ecosystem: balancing innovation with accountability. Companies developing similar tools may face pressure to implement stricter controls, such as identity verification or usage monitoring, to prevent misuse. Meanwhile, the geopolitical implications of such incidents could lead to tighter regulations or restrictions on cross-border collaboration in cybersecurity and AI development.
Key takeaways
- Open-source AI tools for cybersecurity can become vectors for attacks, creating reputational and operational risks for developers. Founders should assess whether their tools could be weaponized and plan mitigation strategies.
- Regulatory scrutiny on AI and cybersecurity tools is likely to increase, particularly for those with cross-border applications. Operators should monitor evolving compliance requirements in their target markets.
- Incidents like this could accelerate the adoption of closed-source models for high-risk tools, potentially limiting collaboration but reducing exposure to misuse.
- For enterprises, this serves as a reminder to audit third-party tools—especially open-source ones—for potential vulnerabilities or misuse in their supply chains.
- Geopolitical tensions may influence how AI and cybersecurity tools are developed, shared, or restricted, impacting global innovation ecosystems.
FAQ
What was ARTEX originally designed for?
ARTEX was an open-source AI agent created to automate penetration testing, helping organizations identify vulnerabilities in their networks by connecting to external large language models like ChatGPT, Claude, and DeepSeek.
Why did the developer make ARTEX closed-source?
The developer cited misuse of the tool, specifically its alleged involvement in cyberattacks on South Korean banks, as the reason for discontinuing its open-source availability and halting updates or maintenance.
Who was identified as the likely perpetrator behind the cyberattacks?
US cybersecurity firm Crowdstrike identified a 26-year-old China-based suspect as the likely perpetrator, who allegedly used ARTEX and Anthropic’s Claude Code in the attacks.
How has South Korea responded to the cyberattacks?
South Korean police have launched an investigation into the attacks, which targeted at least nine banks. President Lee Jae Myung has also called for robust response measures to address the cyber threats.
Related on Lazyfounder
Sources
- Mint (Technology) · 2026-10-09
Chinese developer makes ARTEX AI agent closed-source after Korean bank hack
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


