Current outcome
South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account denying involvement. The ARTEX developer has now closed the project and removed the original GitHub repository, though the source code has been backed up by others.
Progress timeline
2 material updates- #01
韩国多家金融机构疑遭AI攻击,黑客在Claude Code留下身份线索
South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account now denying involvement.
Source evidence: theblockbeats
- #02
卷入韩国银行AI网攻后,ARTEX作者宣布闭源,GitHub仓库已下架
ARTEX developer Autumn-27 announced on October 8 that the project is going closed-source, stopping updates and no longer releasing new versions or providing maintenance support; the original GitHub repository was subsequently removed. The source code has been backed up by other developers.
State after update: South Korean regulators and CrowdStrike have linked data breaches at seven-plus financial institutions, affecting tens of thousands of customers, to an attacker using the open-source agentic pentest framework ARTEX driven by DeepSeek v4.1-flash along with Claude Code, GLM-5.3 and Grok 4.6, with a suspect Telegram account denying involvement. The ARTEX developer has now closed the project and removed the original GitHub repository, though the source code has been backed up by others.
Source evidence: theblockbeats