In brief: A suspected Chinese attack system built from freely available open-source AI agent frameworks autonomously compromised Taiwanese government and energy systems over four days and stole more than 2,500 personnel records.
The security firm Dream has documented a multi-day attack on Taiwanese government and energy infrastructure in which up to eight AI agents operated largely on their own. For CISOs, the case marks a turning point: autonomous attack tools can apparently already be assembled from freely available open-source components.
According to Dream, the campaign ran over four days in early July. At times, the attackers deployed up to eight autonomous agents in parallel, spread across a total of twelve documented attack waves. The system first mapped 21 government systems, then compromised at least 85 user accounts and stole more than 2,500 personnel records. Over the course of the campaign, activity expanded to Taiwan’s nuclear safety authority, at least seven energy companies, and additional government service providers. Within the attack waves, individual sub-agents each took on their own tasks: obtaining credentials, collecting datasets, exploiting a discovered vulnerability in signature verification, and installing backdoors.
Dream stated that it came across a 160-megabyte online archive containing 1,395 files as part of ongoing threat monitoring. The analysis found that the attack tool was built on the freely available, open-source agent frameworks Hermes and OpenClaw – both originally developed not for offensive purposes but to enable language models to autonomously carry out multi-step tasks. The researchers were unable to determine which specific language model powered the agents. The attackers did, however, circumvent its built-in safeguards by presenting the intrusion to the model as an authorized penetration test rather than an actual attack.
In Dream’s assessment, the real significance of the case for security leaders lies less in the fundamental attack capability itself than in the fact that such a powerful, autonomously operating tool was assembled entirely from freely accessible components that any developer can download and run. The researchers also cite the system’s ability to continuously develop new attack strategies on its own, rather than following a preprogrammed sequence, as its most striking feature: the platform continuously re-evaluated available findings, reprioritized attack paths accordingly, and, when attempts failed, tasked another agent with searching the internet for alternative approaches.
Amir Becker, Chief Strategy Officer at Dream and former head of cyber operations at Israel’s Unit 8200, described the incident as, in his experience, an unprecedented, fully autonomous attack on a government target. In his assessment, a permanently assumed state of compromise must now be the only realistic starting point for one’s own security planning. According to people familiar with the case cited by the Financial Times, which first reported on the incident, Taiwan was the actual target of the attack, although Dream itself did not officially confirm the target country. As an indication of Chinese origin, the researchers note that the attack tool’s internal documentation was written in simplified Chinese characters, while the stolen data came back in traditional Chinese characters, as used in Taiwan.