Connect with us

NEWS

ARTEX Developer Pulls AI Security Tool After Links To Bank Hacks

Published

on

ARTEX Developer Pulls AI Security Tool After Links To Bank Hacks

ARTEX Developer Pulls AI Security Tool After Links To Bank Hacks

ARTEX’s developer has ended public releases and maintenance.

CrowdStrike linked the tool to attacks on South Korean financial institutions.

Investigators found AI session records and configuration files on attacker-controlled servers.

The findings describe human-directed attacks assisted by AI, with the suspect’s identity still unconfirmed.

October 09, () – The developer of ARTEX, an artificial-intelligence tool built for security testing, has withdrawn public access after researchers linked it to cyberattacks against South Korean financial institutions.

Operating under the GitHub name Autumn-27, the developer announced the decision on Thursday, October 8. Reuters reported the withdrawal on Friday and confirmed that the project’s GitHub page had been taken down.

“No further versions will be released to the public nor will maintenance support be provided”, the developer said, citing misuse.

FEDERAL REPUBLIC OF NIGERIA GENERAL ELECTION COUNTDOWN
◷ 00:00:00 WAT
✓ YOUR VOTE • YOUR VOICE • YOUR FUTURE
NIGERIA GENERAL ELECTION

Every second brings Nigerians closer to exercising their democratic right and shaping the future of our nation.

📅 16 January 2027
📍 Nigeria
⏰ 12:00 AM WAT
📆
000
DAYS
🕐
00
HOURS
⌛
00
MINUTES
⏱
00
SECONDS
🇳🇬 COUNTDOWN PROGRESS 0%
🪪 Voter Information
✅ Vote Peacefully
🇳🇬 Nigeria Decides
✓
ELECTION DAY IS HERE!

Exercise your democratic right responsibly, peacefully and lawfully.

What Researchers Found
Programming code displayed on a laptop Source Christina Morillo Pexels

In its October 7 investigation, cybersecurity company CrowdStrike said it found ARTEX configuration files and records of Claude Code sessions on infrastructure associated with the attacks. Those records indicated activity against South Korean financial organisations between late September and early October.

Advertisement
Connect with Media Today
Channel
Media Today Facebook
f Join Facebook Page
Media Today WhatsApp Group
◉ Join WhatsApp Group
Media Today WhatsApp Channel
◉ Join WhatsApp Channel
Media Today Telegram
➤ Join Telegram Channel
Media Today Google News
G Follow on Google News
Media Today Google Discover
G Add Us on Google Discover
Media Today Nairaland
N Follow Us on Nairaland

ARTEX belongs to a category of software used for penetration testing, in which security teams probe systems for weaknesses. Such testing requires permission from the system’s owner. The same capabilities can also be directed at systems without authorisation.

CrowdStrike’s findings describe an attacker using AI tools alongside conventional hacking methods. They do not establish that an AI system independently selected the victims or decided to steal their information.

The company also found requests for help locating markets for stolen Korean data. However, it cautioned that personal details discovered in a separate AI session could not be definitively tied to the attacker.

At least nine South Korean banks had disclosed or been reported as targets since late September, according to Reuters. South Korean police opened an investigation.

Adam Meyers, CrowdStrike’s senior vice-president of counter adversary operations, said the technology “allows one human to target many customers in a very short period of time”.

Banking Security Beyond the Customer App
CrowdStrikes office in Sunnyvale California Source Coolcaesar Wikimedia Commons

For Nigerian banks and fintech companies, the investigation offers a specific area for scrutiny beyond their main websites and customer-facing apps.

CrowdStrike cited industry accounts of intrusions involving a loan-progress inquiry service used by financial brokers and an employee mobile work-support system. It did not independently confirm every reported breach, and its report left the total number of affected organisations unresolved.

Those examples suggest that a bank’s security review needs to cover the smaller systems through which staff and intermediaries access information. A customer may never use such a service directly, although it could still hold their personal details.

Nothing in the reports reviewed establishes that Nigerian institutions were targeted in this campaign. Nor does the withdrawal establish that previously downloaded copies of ARTEX have stopped working.

The developer said the software was intended to help organisations assess security risks and opposed illegal use. The statement did not specifically address the South Korean attacks.

CrowdStrike has published technical indicators associated with the campaign, giving security teams information they can check against their own network records while the investigation continues.

Advertisement

READ THIS  Aba North Mayor Rec‌eives Newly Inaugura⁠ted Labour‍ Party Shoe Plaz‍a Executiv‍es,‍ Urges U‌nity Ahead‌ of Electio⁠ns


DO YOU WANT TO WHISTLEBLOW, REPORT FRAUD, THEFT OR INJUSTICE OR INTIMIDATION? SEND US YOUR STORY/REPORT TO NEWSDESK@MEDIATODAY.NG

Continue Reading
Advertisement
Click to comment

Leave a Reply

Enable Notifications OK No thanks