Skip to main content

ARTEX developer ends updates after South Korean bank attacks

9 OCTOBER 2026·2 MIN READ·2 SOURCES

ARTEX’s Chinese developer has made the AI agent closed-source and said the project will receive no further updates, public versions or maintenance support. Reuters reported that cybersecurity firms identified ARTEX as a tool used in a recent cyberattack campaign against South Korean banks.

ARTEX developer ends updates after South Korean bank attacks

Key takeaways · 4

  • 01

    The developer says ARTEX will no longer receive updates, public releases or maintenance support.

  • 02

    AhnLab found ARTEX instances on about 600 IP addresses and traced links to more than 600 additional addresses.

  • 03

    AhnLab warns that an ARTEX instance could be used for legitimate security work, so its presence alone is not proof of an attack.

  • 04

    South Korean authorities say intrusions affected several banks and other financial institutions, and police are investigating.

A multi-agent testing framework

AhnLab describes ARTEX as an open-source, large-language-model-based autonomous penetration-testing framework.[2] Its design divides vulnerability identification, validation, attack planning and execution among multiple AI agents.[2] AhnLab also noted that the project documentation and user interface are mostly written in Chinese, and that its account identified a possible connection to a WeChat-based Chinese security community.[2] Those details help describe the project and its context, but do not establish who operated any particular instance or why it was running.

IP findings have limits

AhnLab’s Security Intelligence Center found ARTEX instances hosted on about 600 IP addresses worldwide, then identified more than 600 additional IP addresses by tracing links from previously identified ARTEX server IPs.[2] AhnLab cautioned that the addresses cannot all be assumed to belong to one group or infrastructure.[2] It also said red teams, penetration testers and security researchers may use ARTEX, so finding an instance alone does not establish malicious activity.[2] AhnLab found CyberStrikeAI running on multiple IP addresses also hosting ARTEX, but said that overlap does not prove the tools were used by the same actor or in the same campaign.[2]

The bank investigation continues

South Korean authorities said intrusions affected Shinhan, KB Kookmin, Hana and BNK Busan banks, as well as two savings banks and Hyundai Capital; police were investigating.[2] The available evidence does not identify ARTEX as the tool used in each intrusion or establish a link between every affected institution and a specific ARTEX server. AhnLab assessed that AI attack tools can lower barriers for less-skilled attackers and help experienced attackers increase the speed and scale of operations.[2] For defenders, that assessment is a reason to evaluate exposure and activity carefully, not to treat an IP match as attribution.

The end of updates and support changes the maintenance picture for teams using or monitoring ARTEX. AhnLab’s cautions also underline why defenders should separate indicators that warrant investigation from evidence that establishes malicious use or attribution.

Why it matters
Daily session

Put this to work — one session a day, built for your industry.

Create a free account for a daily session — eight questions and one real-work challenge, on the news that affects your role.

Start free

How this developed

  1. 9 October 2026

    ARTEX developer ends updates after South Korean bank attacks

Sources

AI fluency, one session a day, built for your work.