AI

Autumn-27 Pulls ARTEX AI Pentest Tool After Cyberattack Misuse

Autumn-27 said malicious use goes against ARTEX's original purpose of helping organizations check security risks within authorized scope.

Autumn-27 is making its AI penetration testing tool ARTEX private and halting all updates, new version releases and maintenance support, citing malicious use.

Autumn-27 said the tool was created to help companies and organizations check security risks within an authorized asset scope, and that malicious use goes against that original purpose.

The developer also stated that the recent cyberattacks were unrelated to it, according to digitaltoday.co.kr.

In October 2025, the Hacker News reported that Autumn-27 said the attacks were unrelated to the company and that malicious use contradicts the tool's intended purpose. ARTEX had been provided as open source and is an autonomous penetration testing system based on LLM-based multi-agents.

According to an analysis by CrowdStrike published at that time, hackers used ARTEX and large language models in attacks targeting South Korea's financial sector. Those attacks took place from late September to early October 2025 and data was actually leaked. The attacker has not been identified, though CrowdStrike considers Chinese-speaking financially motivated actors as suspects.

Quick answers

Why is Autumn-27 making ARTEX private?

Autumn-27 said malicious use goes against the tool's original purpose, which was to help companies and organizations check security risks within an authorized asset scope.

Will ARTEX still receive updates?

No. Autumn-27 said it is halting all updates, new version releases and maintenance support.

Who used ARTEX in the attacks?

The attacker has not been identified, but CrowdStrike considers Chinese-speaking financially motivated actors as suspects.

Source