CMSC
0.1700
Chinese AI cybersecurity tool Artex said it stopped programmers from accessing its source code, acknowledging misuse by "bad actors" after South Korea linked it to several recent bank hacks.
Artex was designed to help organisations strengthen their cyber defences through security testing to find potential weak points.
But the South Korean government said this week it was "highly likely" Artex had been used in data breaches at more than seven financial institutions, including major banks.
Artificial intelligence's ability to find previously unknown ways to hack into computer systems is in the global spotlight, as leading labs release ever-more advanced models.
Artex was "abused by some bad actors" to launch cyberattacks, the tool's developer "Autumn-27" wrote Thursday on code-hosting platform GitHub.
"Given the misuse of the tool, the Artex project will no longer be updated and will be converted to closed-source," the developer said.
"No further versions will be released to the public, nor will maintenance support be provided."
Artex had been open-source -- allowing programmers to download its underlying code and customise it to suit their purposes.
Using Artex for cyberattacks was "entirely contrary to" the developer's intentions, they added, without referring directly to the alleged South Korean cases.
South Korea's Financial Services Commission says more than 68,000 people have been affected by the hacks.
Shinhan Bank, one of the breached institutions, said information attached to loan applications for about 25,000 customers had been leaked -- including names, phone numbers and annual income.
- 'Financially motivated' -
In Japan, meanwhile, around 20 companies have said their data may have been compromised in a spate of similar cyberattacks potentially impacting millions of customers.
The Japanese government has called on companies to strengthen their cyber defences.
"At this stage, it is not clear what the background to these cases is or whether there are any links between them", Japan police chief Yoshinobu Kusunoki said on Thursday.
As AI makes hacking more sophisticated, "the scope of the damage is spreading across all areas on a scale that is difficult to compare with the past", South Korean President Lee Jae Myung said on Tuesday.
US cybersecurity giant CrowdStrike said on Wednesday that its investigations into digital clues suggested the attacker had used Artex, and was potentially a 26-year-old based in China.
"The threat actor is likely a Chinese speaker and financially motivated," a CrowdStrike blog post said.
Experts told AFP that Artex going closed-source would make the code harder for new users to obtain and adapt.
But the decision "cannot remove copies already downloaded or prevent people from continuing to use them", said Poe Zhao, founder of the analysis publication Hello China Tech.
"Because the code was public, people could download it, change it and run it themselves. The developer could ask users to follow the rules, but had little control over their actions," he added.
Ilya Kulyatin, CEO of Foundry Labs and founder of the Tokyo AI (TAI) tech community, said users of open-source programmes can "remove restrictions built into the tool" which "makes certain forms of misuse easier".
"But openness also benefits defenders: researchers can inspect the code, identify weaknesses and improve protection."
A.El-Sewedy--DT