A Chinese developer has shut down its open-source tool ARTEX and moved it to closed source after cybersecurity firms tied it to a wave of attacks on South Korean banks. "Given the misuse of the tool, the ARTEX project will no longer be updated and will be converted to closed source. No further versions will be released to the public nor will maintenance support be provided," the developer, who uses the GitHub handle "Autumn-27", wrote on Thursday. The project's GitHub page has since been taken down.

ARTEX is not a language model of its own. It is an agent that automates penetration testing by driving external models — ChatGPT, Claude and DeepSeek among them — to help organisations probe their own networks. That is precisely what makes the episode awkward: the tool is dual-use by construction. The same automation that helps a company test its defences lowers the technical bar for an attacker and speeds up the work considerably.

US cybersecurity firm CrowdStrike said the suspect behind the attacks on South Korean banks is likely a 26-year-old based in China who used ARTEX together with Anthropic's Claude Code. The campaign's aim was reportedly the theft of customer data. At least nine South Korean banks have disclosed attacks or been named as targets in local media since late September; police opened a probe this week, and President Lee Jae Myung called for a robust response. China's foreign ministry spokesperson Mao Ning said the ministry was not familiar with the case and that China consistently opposes and combats hacking.

The developer said ARTEX was originally intended to help enterprises and organisations conduct security risk testing, and, without addressing the bank attacks directly, opposed any illegal use and disclaimed responsibility for conduct that breaks laws or regulations.

The episode lands on a sore spot of the agent era: public debate focuses on the models, while much of the operational risk sits in the automation shells around them. Pulling a project does not undo that — copies already distributed remain, and the capability now exists in many tools. For security teams the practical lesson is less dramatic than the dispute: attacks assembled from off-the-shelf agents and commercial models can only be spotted through the same signals that legitimate automation produces.