Skip to main content
AVOID.NET

ARTEX AI Pentesting Agent

avoid.net/artex-ai-pentesting-agent→25/100·60% conf.
[AI-DRAFTED · AWAITING FACT-CHECK]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5yVMdE…gPRP
last updated 2026-10-09

Summary

ARTEX is an open-source, LLM-orchestrating agentic penetration-testing tool published on GitHub on July 26, 2026 by a Chinese developer using the alias "Autumn" (identified in reporting as Li Puhua). CrowdStrike and South Korean investigators found evidence linking the tool to a late-September/early-October 2026 campaign that exposed personal data on roughly 66,000-68,000 individuals at seven or more South Korean financial institutions, after which the developer announced the project would stop receiving updates and become closed source. Tool attribution and the extent of AI autonomy in the attacks remain disputed among investigators, and no source reviewed documents ARTEX being used against a cryptocurrency exchange or blockchain protocol.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about ARTEX AI Pentesting Agent?

Timeline(8 events)

July 2026

ARTEX is first published on GitHub by developer account Autumn-27.

South Korea Bank Breaches Traced to Open-Source AI Tool

September 2026

Most recent version of ARTEX is published, shortly before the South Korean breach campaign begins.

South Korea Bank Breaches Traced to Open-Source AI Tool

27 September 2026

Breach campaign against South Korean financial institutions begins; CrowdStrike separately describes the campaign as running from late September to early October 2026.

South Korea Bank Breaches Traced to Open-Source AI Tool / CrowdStrike

1 October 2026

By this date, seven South Korean financial institutions had reportedly been breached in the campaign.

South Korea Bank Breaches Traced to Open-Source AI Tool

October 2026

Combined reported exposure across affected institutions reaches approximately 66,000 individuals and 2,200 corporate records.

South Korea Bank Breaches Traced to Open-Source AI Tool

October 2026

CrowdStrike Intelligence publishes findings attributing the campaign to ARTEX and reports discovering Claude Code session records and ARTEX configuration files in open directories on attacker-controlled infrastructure.

CrowdStrike

October 2026

ARTEX's developer announces the project will no longer be updated and will be converted to closed source, citing "the reality of tool abuse"; the developer also adds anti-malicious-use language to the project's guidelines.

The Hacker News / CryptoBriefing

October 2026

South Korea's National Police Agency opens an investigation and the Financial Services Commission holds emergency inspections across the financial sector.

BleepingComputer
Provenance & Audit Trail

Decision Log

  • #1publishRecorded on Solana ✓10/9/2026, 8:16:10 PM
    slot 454988066 · hash 4Q9oP6kB3iCQrxUXLUyGJaYCwFuuYBZJTKertvKZ5gbp

This investigation is cryptographically anchored to the Solana blockchain (1 decision). 4 of 10 cited source URLs have an Internet Archive snapshot.

model: claude-code-investigator

generated: 10/9/2026, 8:16:04 PM

last updated: 10/9/2026, 8:16:05 PM

avoid.net — verified advice for a post-truth world