ARTEX developer halts public distribution and updates of Chinese-made AI tool suspected of being used in latest wave of hacking attacks
A recent series of AI-backed cyberattacks on South Korean banks may be linked to a Chinese group that carries out distributed denial-of-service (DDoS) attacks for hire, according to a report released Sunday by a Seoul-based cybersecurity firm Logpresso.
The company said the Telegram account “YY520CN,” linked to the bank hackings, was listed as a moderator of an online community called GodNet in September 2024. The community was created by Vitas, a Chinese group that carries out DDoS attacks for paying clients.
DDoS attacks flood websites or online services with traffic, overloading systems and preventing users from accessing them.
The findings by Logpresso stems from analysis of a report released earlier this month by US cybersecurity firm CrowdStrike, which compared Telegram and GitHub records with data stolen by malware known as an “infostealer.” The malware collects passwords and other login details from infected devices.
The Korean security firm also traced details of a second account on the GodNet staff list.
Logpresso examined GitHub code linked to that member and found a connection between a Telegram account and a GodNet domain name. It also found an email address in the code’s edit history and traced it to login details stolen by infostealer malware in 2023.
The suspected member appeared to have been infected with password-stealing malware, exposing the accounts and services they used. The stolen data included login details for Microsoft and Oracle cloud services, suggesting that the member may have helped run the group’s technical systems, according to Logpresso.
The second GodNet member has not been directly linked to the bank hacks, but Logpresso said investigators could identify the account’s operator by comparing the stolen login data with cloud providers’ subscriber records, which could also help them trace the person behind YY520CN.
But the company said the account links alone do not establish who carried out the hacks, and it could not conclude that only one person was behind the breaches.
The identity of the YY520CN account’s operator also remains unclear. CrowdStrike disclosed the Telegram username after examining AI-use records on a server linked to the attacks. The account was deleted on Oct. 8, after the report was released.
A new account later appeared under the same username, with a linked channel posting a denial of involvement. It remains unclear whether the same person controlled both accounts.
The owner of the phone number linked to YY520CN also denied involvement, saying someone had used their number without permission. Logpresso said it needed more information to verify the person’s identity.
South Korean authorities investigating the latest wave of cyberattacks suspect that the attacker combined multiple AI models, including DeepSeek, with ARTEX, a Chinese-made AI-powered penetration-testing tool. The attacker reportedly used Hong Kong-based control servers, separate attack servers and alternative access routes to target seven South Korean financial institutions in succession.
According to Reuters and other news outlets, ARTEX’s developer announced on GitHub that further updates and public distribution of the tool would be halted, citing its misuse in cyberattacks.
The developer, who goes by “Autumn-27” on GitHub, said the tool would no longer be updated and would be switched to a closed-source model because of its misuse.
junheee@heraldcorp.com


