An 'autonomous hacking tool' built with AI agents attacked government agencies in Asia, possibly a Chinese attack on the Taiwanese government.

It has been reported that a hacker believed to be from China compromised a Taiwanese government website using publicly available AI tools. According to researchers at Israeli AI company
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia | | Dream Security Blog
https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia
China-linked hackers hit Taiwan in unprecedented 'autonomous' AI cyber attack
https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795
For four days in early July 2026, a hacking tool utilizing AI agents deployed up to eight autonomous agents simultaneously, mapping 21 government systems, investigating vulnerabilities, and changing tactics if blocked. In one instance, it reportedly gained access to a database of thousands of employees without authentication. According to Dream's investigation, the attackers obtained 1,395 files, 85 sets of credentials, and over 2,564 employee and related personnel records. It has also been revealed that the attacks subsequently expanded to include Taiwan's Nuclear Safety Agency and at least seven energy companies.
Dream stated, 'This incident clearly demonstrates that while the cost of executing sophisticated attacks has decreased significantly, the cost of defending against such attacks remains high.' Dream's Chief Strategy Officer, Amir Becker, added, 'I previously commanded cyber operations in Israel's elite signal intelligence unit, Unit 8200, and I have never seen an end-to-end autonomous attack like this targeting a government agency.' According to Becker, the advent of AI tools means that governments around the world must assume they are constantly under cyberattack.
Dream has only described the target of the attack as 'an Asian government agency,' citing company policy to refuse to disclose details of the government. However, according to information obtained by the Financial Times from a source familiar with the attack, the target was Taiwan. Dream has also not definitively attributed the attack to a specific group, but has pointed out that the use of simplified Chinese in internal communications related to the hacking strongly suggests that the attackers may be connected to China.
Furthermore, Dream has published its findings on the structure of the 'multi-agent AI framework' used in this attack. According to Dream, the attack used a framework based on AI agents called ' Hermes ' and 'OpenClaw .' This framework allows up to eight sub-agents to operate in parallel for each attack, each assigned to a different target and attack method. In the 12 attacks observed over four days, these agents were recorded with agent names from A to Q, each automatically attempting to access government employee credentials, breaching 85 accounts, leaking hundreds of personnel records from unauthenticated API endpoints, discovering a vulnerability in signature verification in the government's personal authentication service, and installing a persistent backdoor in government web applications.

What distinguishes this framework from conventional attack tools is that it doesn't simply command the AI to carry out cyberattacks, but incorporates investigation, judgment, execution, and evaluation as a single loop. It appears that the AI agent autonomously performed operations such as 'continuously ranking and reprioritizing 14 parallel attack chains to concentrate efforts on the highest-value targets first,' 'searching vulnerability databases, GitHub repositories, security-related publications, etc., to find new exploitation methods when existing methods become ineffective,' and 'adapting the framework in operation without human intervention through structured post-event reporting that feeds the results of each stage back into the planning of the next stage.' Dream also explains that rejection by the AI model's safety guardrails was avoided by treating all activities as 'approved penetration testing.'

Dream points out that AI-powered attacks are not new, and governments around the world are not prepared to deal with this threat. Just as attackers are carrying out their attacks with sophisticated logic, similarly advanced technology is needed on the defensive side. Defenders also need an 'AI-native' security system that utilizes AI to predict which assets are likely to be targeted and which attack vectors are most likely to be used next.
Related Posts:







