ARTEX AI Pentesting Agent
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·5yVMdE…gPRPSummary
ARTEX is an open-source, LLM-orchestrating agentic penetration-testing tool published on GitHub on July 26, 2026 by a Chinese developer using the alias "Autumn" (identified in reporting as Li Puhua). CrowdStrike and South Korean investigators found evidence linking the tool to a late-September/early-October 2026 campaign that exposed personal data on roughly 66,000-68,000 individuals at seven or more South Korean financial institutions, after which the developer announced the project would stop receiving updates and become closed source. Tool attribution and the extent of AI autonomy in the attacks remain disputed among investigators, and no source reviewed documents ARTEX being used against a cryptocurrency exchange or blockchain protocol.
Connected Entities
1 entityNo connected entities recorded yet — this investigation is not currently linked to any other page in the index.
Timeline(8 events)
July 2026
ARTEX is first published on GitHub by developer account Autumn-27.
South Korea Bank Breaches Traced to Open-Source AI ToolSeptember 2026
Most recent version of ARTEX is published, shortly before the South Korean breach campaign begins.
South Korea Bank Breaches Traced to Open-Source AI Tool27 September 2026
Breach campaign against South Korean financial institutions begins; CrowdStrike separately describes the campaign as running from late September to early October 2026.
South Korea Bank Breaches Traced to Open-Source AI Tool / CrowdStrike1 October 2026
By this date, seven South Korean financial institutions had reportedly been breached in the campaign.
South Korea Bank Breaches Traced to Open-Source AI ToolOctober 2026
Combined reported exposure across affected institutions reaches approximately 66,000 individuals and 2,200 corporate records.
South Korea Bank Breaches Traced to Open-Source AI ToolOctober 2026
CrowdStrike Intelligence publishes findings attributing the campaign to ARTEX and reports discovering Claude Code session records and ARTEX configuration files in open directories on attacker-controlled infrastructure.
CrowdStrikeOctober 2026
ARTEX's developer announces the project will no longer be updated and will be converted to closed source, citing "the reality of tool abuse"; the developer also adds anti-malicious-use language to the project's guidelines.
The Hacker News / CryptoBriefingOctober 2026
South Korea's National Police Agency opens an investigation and the Financial Services Commission holds emergency inspections across the financial sector.
BleepingComputerDecision Log
- slot 454988066 · hash 4Q9oP6kB3iCQrxUXLUyGJaYCwFuuYBZJTKertvKZ5gbp
This investigation is cryptographically anchored to the Solana blockchain (1 decision). 4 of 10 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 10/9/2026, 8:16:04 PM
last updated: 10/9/2026, 8:16:05 PM
avoid.net — verified advice for a post-truth world