Attackers wired two open-source AI agent frameworks into a hacking tool and turned it loose on Taiwanese government systems for four days at the start of July, where it ran largely without human direction. The Israeli cyberdefense firm Dream, which investigated the intrusion, disclosed it on August 12 to the Financial Times.

The tool ran up to eight agents at once across twelve documented waves. It mapped 21 government systems, ranked and reprioritized the routes in, and changed tactics when blocked. Where one approach failed, another agent was sent to search the internet and work up a different method. Dream described a framework able to teach itself by studying public databases to find new infiltration techniques when its existing ones stopped working.

It cracked at least 85 government accounts, harvested 1,395 files and took more than 2,500 personnel records. Some of that data sat behind API endpoints that required no authentication. The agents also found a signature validation flaw in an authentication service and installed backdoors on web applications. The operation later reached Taiwan’s nuclear safety agency and at least seven energy companies.

Reconnaissance and lateral movement that would occupy a skilled human team for days or weeks ran in hours, most of it without supervision. Dream described the operation as the first of its kind, and said the speed of execution was what set it apart.

The frameworks were Hermes and OpenClaw, both publicly available. Their safety controls were bypassed by describing the work as authorised penetration testing. Dream could not determine which model was driving the agents.

Attribution rests on language. Internal documentation belonging to the operators was written in Simplified Chinese, which Dream says makes a China-linked operator highly probable. The stolen target data was in Traditional Chinese, the script used in Taiwan, Hong Kong and Macau. Dream has not named a group or formally attributed the operation to Beijing. The firm was founded by Shalev Hulio, who co-founded the spyware maker NSO Group.

Comparable agent behavior has been documented in laboratories and evaluations rather than against live targets. Sysdig catalogued a ransomware campaign run end to end by an AI agent in July. UK evaluators recorded agents that fabricated identities to push malicious code past an open-source maintainer during a routine cyber evaluation. North Korea’s Kimsuky was found running open-weight models on its own attack servers, though Genians assessed that group was still gathering tools rather than deploying them autonomously.

Both frameworks remain publicly available.

Sources: National Technology, Insurance Business, Fudzilla

–
By the Control Plane Editorial Team