Skip to main content
Emerging ThreatsMalware & Ransomware

Hackers Deploy AI for Near-Autonomous Attack on Taiwan Government

Government office interior with computer workstations, personnel, and network equipment near a large window.

More than 2,500 personnel records were extracted in what researchers called a “near-autonomous attack” — the first publicly known case of an autonomous AI-driven cyber operation striking a government target, according to a report by Israeli cyber firm Dream published Wednesday.

Dream’s description: “adapt mid-operation without human intervention”

Dream said the attackers set up a framework that could “adapt mid-operation without human intervention.” The firm described the campaign as a “near-autonomous attack” that implemented dedicated research phases it calls “Learning Cycles” — “autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure.”

Dream also highlighted that the operation “didn’t stop at primary targets,” expanding to additional systems and learning from mistakes as it progressed.

Targets named in the report: Taiwanese government, supply chain, nuclear safety, email, energy firms

The Dream research tied the operation to a government target in Taiwan and said the attackers extracted more than 2,500 personnel records, among other data. The framework expanded the operation to “government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies,” scanning them all in parallel for “misconfigurations, exposed admin interfaces, and exploitable vulnerabilities.”

Tools and discovery: Hermes, OpenClaw, and a 160MB archive

According to Dream, the attackers used two popular open-source AI frameworks, Hermes and OpenClaw, to set up the Taiwan operation. Dream said the operators bypassed safety guardrails by framing the work as authorized penetration testing. The firm discovered the operation via an online archive of 160 megabytes and nearly 1,400 files, which Dream said revealed “a multi-agent AI system that achieved confirmed, real-world compromises against state infrastructure.”

Technical sophistication: Bayesian prioritization, self-correction, and human tuning

Dream emphasized that while the campaign was highly automated, building a system that “actually works at this level” required more than “just” running a model. The report identifies sophistication in “Bayesian prioritization, self-correction loops, and adaptive research cycles,” and notes that success demanded “careful adjustment to the specific task, optimization of agent coordination, and fine-tuning of decision logic.”

The firm contrasted this operation with an autonomous cyber espionage campaign reported last fall, saying Anthropic had stopped that earlier campaign even though researchers noted it “still required significant human work.” Dream’s account similarly signals that human tinkering remained necessary, even as the framework achieved mid-operation adaptation.

What this means for technologists and security teams, policymakers and regulators, and affected enterprises and procurement leaders

  • Technologists and security teams: Watch for multi-agent AI frameworks and “Learning Cycles” that can search vulnerability databases, GitHub, and security research publications autonomously; expect adversaries to combine open-source models with automation that prioritizes and self-corrects in real time.
  • Policymakers and regulators: The report’s expansion of targets to a nuclear safety agency, government email systems, and multiple energy-sector companies underscores cross-sector risk to state infrastructure and critical services; regulatory scrutiny may focus on how open-source AI tools are repurposed and how pen-test framing can be abused to bypass guardrails.
  • Affected enterprises and procurement leaders: The attackers’ parallel scanning of government IT supply chain vendors and the targeting of misconfigurations and exposed admin interfaces highlight the importance of supply-chain visibility and configuration hygiene in vendor ecosystems.

Dream’s findings portray a cyber operation that blends automation with engineered sophistication and human refinement: a multi-agent system using open-source AI frameworks, an archive of operational files, and adaptive research cycles that probed government infrastructure and its suppliers. The public disclosure — first reported by the Financial Times and published by Dream — leaves a stark practical question for network defenders and risk managers alike: how many similar frameworks exist unobserved, and where else might they already be probing for misconfigurations and exposed interfaces?

Source: CyberScoop — Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan