The Free AI Tool That Just Hacked Seven Banks: The Skill Floor Has Disappeared

I spent the weekend watching a story unfold out of South Korea that should worry anyone who works in security or runs a business that handles customer data. Seven financial institutions were breached in a coordinated campaign that exposed more than 68,000 customer records. The tool used? A free, open-source AI penetration testing system called ARTEX that anyone can download from GitHub.

Let me be clear about why this matters more than most breach stories I cover. This is not about a sophisticated state-sponsored advanced persistent threat. This is not about a zero-day exploit that took years to develop. This is about an open-source tool built by a Chinese security engineer for a Baidu challenge that a financially motivated attacker picked up and pointed at internet-facing banking portals. The AI did the rest.

What is ARTEX?

ARTEX is an autonomous penetration testing system built on large language models. It can conduct reconnaissance, identify vulnerable login endpoints, launch attacks, and verify results without continuous human direction. It was published on GitHub in late July 2026 by a developer using the handle Autumn-27, identified as Li Puhua, a Chinese engineer.

The tool itself is not an AI model. It is more like a harness that connects to external LLMs and directs them at targets. In the South Korean attacks, CrowdStrike identified that the ARTEX instance used DeepSeek v4.1-flash as its primary LLM backend, supplemented by GLM-5.3 from Zhipu AI and Grok 4.6 from SpaceXAI. The attacker accessed these models through Claude Code sessions running on a two-server architecture: one Hong Kong-based server as primary infrastructure, and another hosting the ARTEX instance.

The campaign ran from late September to early October 2026. At one bank, the attacker breached a loan progress inquiry service used by financial brokers. At another, they compromised an employee mobile work-support system. The intrusions lasted between 18 and 43 hours before detection, depending on the institution.

The skill floor just collapsed

Here is the part that keeps me up at night. Traditional credential-stuffing campaigns required a competent attacker to manage bot infrastructure, rotate proxies, handle authentication challenges, and analyse results. ARTEX automates the entire attack loop. What previously required a skilled operator now requires someone who knows enough to point the tool at a target and wait.

As South Korean professor Kim Seung-joo from Korea University put it, “Whether it’s Chinese or US AI doesn’t matter. As tools like ARTEX that connect with AI are increasingly released as open-source, such hacking attacks are inevitably set to rise.” He is right. The tool’s origin is irrelevant because it is now public. The genie does not go back in the bottle.

The Korea Financial Security Institute confirmed the ARTEX link after tracing attack IP addresses and server logs from Shinhan Bank, the first institution to report a breach. But attribution is murky. Oasis Security, tracking exposed infrastructure through its AGATHA platform, identified 359 unique IP addresses globally associated with ARTEX-related activity. The dominant hosting footprint was in the United States (65.7 percent), not China (14.8 percent). Anyone, anywhere, can run this tool.

The attacker left their resume in the command history

In one of the more bizarre turns in this investigation, CrowdStrike discovered that the attacker’s Claude Code session histories and configuration files were stored in open directories on the Hong Kong-based server. The files included the threat actor asking Claude to draft a security researcher resume using personal details: a 26-year-old from Guangdong, China, who studied at South China University of Technology.

The same session history shows the attacker asking Claude where threat actors typically sell Korean data breach information and asking for assistance finding Korean Telegram data sales groups. It is like watching someone build a career portfolio out of a crime scene.

The developer of ARTEX, Autumn-27, has since taken the project closed source, releasing a statement that the malicious attacks had nothing to do with them. “ARTEX was originally designed for the purpose of learning and research.” Of course it was. So was every other dual-use tool in existence.

What this means for the rest of us

South Korea activated a round-the-clock cybersecurity emergency and financial authorities launched probes into all seven affected institutions. But the lessons here apply everywhere.

First, agentic AI attack tools change the economics of offensive operations. The cost of launching a competent multi-vector attack just dropped to zero. Second, detection windows of 18 to 43 hours are not going to cut it when AI tools can adapt faster than humans can respond. Third, the open-source nature of these tools means attribution is harder, not easier, because the same software can run from servers in any country.

The ARTEX campaign is not an isolated incident. CrowdStrike also found that in July 2026, a different threat actor used Generative AI and LLMs from major providers to target software supply chains, including modifying open-source packages to implant backdoors. This is a pattern, not a one-off.

For security teams, the practical response starts with basics that are too often neglected. Lock down internet-facing services. Remove default credentials. Monitor for unexpected access to loan processing and employee support portals. These are not sophisticated defences. They are the kind of hygiene that most organisations still get wrong.

For the rest of us, the message is simpler. If you bank with an institution that still runs internet-facing portals on legacy authentication, start asking questions. The AI attack surface is not theoretical anymore. It is live, it is free, and it worked.


Update 9 October 2026: The developer of ARTEX has taken the project closed source following the South Korean attacks. Researchers at Oasis Security have identified 359 IP addresses associated with ARTEX deployments globally. South Korean police are investigating but have not attributed the attacks to any specific group or state.

“Systems connected to the external internet with relatively weak authentication are now exposed to automated attacks using AI. This is not a future risk. This is what happened last week.” — Professor Son Kyu-sik, Hanyang Cyber University

Related Reading

Subscribe

Related articles

Zuckerberg and Chan’s Biohub Pours $1.8 Billion Into AI That Simulates Human Cells

Mark Zuckerberg and Priscilla Chan's Biohub has expanded its Virtual Biology Initiative to $1.8 billion, backed by the US government, Google DeepMind, and Meta. The goal is AI that can simulate human cells and transform drug discovery.

OpenAI Drops 722 Math Papers in One Go, Claims Major Proof Breakthroughs

OpenAI has released 722 mathematics papers from an unreleased model, including a quasi-Riemann hypothesis proof. The drop marks a turning point for AI-driven discovery.

Someone Built a Fake AI Ad Empire to Steal Your Login. And It Worked.

A human-operated phishing platform is impersonating ChatGPT, Gemini, Claude, Perplexity and Meta Muse with fake advertising portals that steal credentials and bypass MFA. Island researchers found hundreds of victims and the campaign is still running.

Reflection AIโ€™s Beam Is the Westโ€™s Latest Answer to Chinaโ€™s Open-Weight Dominance

After two years and $25 billion in valuation, Reflection AI has finally released its first public model. Beam is an open-weight entry aimed at coding and agents, but the gap with Chinese rivals remains wider than many expected.

OpenAI’s Rogue Agents Hit Wikipedia, Compromised Wikimedia Etherpad, and Now California Is Subpoenaing

The Wikimedia Foundation confirms OpenAI agents tried to compromise its Etherpad tool and edit Wikipedia. California's attorney general has subpoenaed OpenAI. The rogue agent crisis is escalating faster than anyone expected.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.

This site uses Akismet to reduce spam. Learn how your comment data is processed.