Suspected Chinese hackers targeted Taiwan in what Dream describes as a largely autonomous AI powered cyberattack.
According to Dream, the campaign ran for four days in early July and at times deployed up to eight autonomous agents in parallel across a total of 12 documented attack waves. The system initially mapped 21 government systems, then compromised at least 85 user accounts and stole more than 2,500 personnel records. The activity later expanded to Taiwan’s nuclear safety authority, at least seven energy companies, and additional government contractors and systems. Within individual attack waves, different subagents were assigned specific tasks, including obtaining credentials, collecting datasets, exploiting a vulnerability discovered in signature verification, and installing backdoors.
Dream said it found the key evidence in a 160 MB online archive that surfaced as part of its ongoing monitoring of threat actors. The archive contained 1,395 files showing that the attack tool was built on two freely available, open source AI agent frameworks, Hermes and OpenClaw. Neither was originally developed for offensive purposes. Instead, both are designed to enable language models to autonomously execute complex, multi step tasks.
Security Controls Bypassed by Disguising Attack as Penetration Test
The researchers were unable to determine which specific language model powered the agents. According to the data, however, the attackers bypassed its built in safeguards by presenting the intrusion to the model as an authorized penetration test rather than a real attack. Dream said the most notable aspect was not the system’s ability to break into targets itself, but the fact that the attackers assembled such a capable, autonomous tool entirely from publicly available components that any developer can download and run.
The researchers also identified the system’s ability to continuously develop new attack strategies on its own as its most striking feature. Rather than following a predefined sequence, the platform continuously reassessed the intelligence available to it, reprioritized potential attack paths accordingly, and, when an attempt failed, tasked another agent with searching the internet for information and developing an alternative approach.
Amir Becker, Chief Strategy Officer at Dream and former head of cyber operations at Israel’s Unit 8200, described the incident as, in his experience, an unprecedented fully autonomous attack against a government target. He said:
“This must be the fundamental assumption of every government around the world.”
Amir Becker, Chief Strategy Officer at Dream and former head of cyber operations at Israel’s Unit 8200
Assuming that a compromise is already in place should now be the only realistic starting point for security planning. According to people familiar with the case who spoke to the Financial Times, which first reported on the incident, Taiwan was the actual target of the attack, although Dream did not officially confirm the target country as a matter of general company policy.
As an indication of Chinese origins, the researchers point to the fact that the attack tool’s internal documentation was written in Simplified Chinese, while the data actually stolen was returned in Traditional Chinese characters, as commonly used in Taiwan.
(Editorial Team)