China-linked Hackers Use AI Agents to Attack Taiwan Government Websites
Key Takeaways Suspected Chinese state-sponsored actors leveraged open-source AI agents for an autonomous cyberattack against Taiwanese government and critical infrastructure. The AI framework, built...
Key Takeaways
- Suspected Chinese state-sponsored actors leveraged open-source AI agents for an autonomous cyberattack against Taiwanese government and critical infrastructure.
- The AI framework, built from Hermes and OpenClaw, compromised at least 85 government accounts and extracted over 2,500 personnel records.
- The autonomous agents targeted 21 government systems, Taiwan’s nuclear safety agency, and seven energy companies.
- This marks a significant escalation in AI-driven cyber warfare, demonstrating machine-driven intrusion with human-like coordination and minimal oversight.
AI-Powered Cyberattack Targets Taiwan Government and Critical Infrastructure
In a significant development for cyber warfare, researchers have uncovered what they describe as the first fully autonomous cyberattack against a foreign government. Suspected China-linked threat actors utilized open-source artificial intelligence tools to infiltrate Taiwanese government websites and critical infrastructure, demonstrating a new level of sophistication in automated cyber operations.
Table Of Content
The operation, brought to light by Israeli AI and cyberdefense firm Dream, signals a notable escalation in the application of AI in cyber warfare. It illustrates that machine-driven intrusions can now achieve a level of coordination previously associated with human hacking teams, fundamentally reshaping the landscape of state-sponsored cyber espionage.
Autonomous AI Framework Utilized in Campaign
According to findings reported by the Financial Times and further detailed by Dream, the attackers constructed an autonomous hacking platform using publicly available AI agent frameworks named Hermes and OpenClaw. This custom system deployed up to eight agents concurrently over a four-day period in early July.
These AI agents autonomously mapped 21 government systems, identified vulnerabilities, adapted their tactics when encountering obstacles, and navigated through targeted networks with very limited human intervention. This capability allowed the operation to progress efficiently and covertly.
The sophisticated tool managed to compromise at least 85 government accounts, leading to the exfiltration of more than 2,500 personnel records. The attack subsequently expanded its reach to include Taiwan’s nuclear safety agency and a minimum of seven energy companies, highlighting the strategic significance of the targets.
Discovery and Operational Details
Dream researchers discovered evidence of this campaign within a 160MB online archive containing 1,395 files, which was exposed during their broader threat-tracking efforts. The archive provided insights into how the AI agents continuously evaluated and re-prioritized attack paths.
A key aspect of the autonomous system was its ability to dynamically adapt: if one attack vector failed, another agent would automatically search the internet for new intelligence and formulate an alternative approach. This self-correcting mechanism allowed the operation to advance without requiring constant input from human operators, a critical factor in its success and stealth.
Intriguingly, safeguards embedded within the underlying AI model were circumvented through a simple prompt-engineering trick. The attackers framed the entire intrusion as an authorized penetration test, enabling the agents to perceive destructive activities as legitimate security research. Researchers were unable to identify the specific large language model powering these agents.
Internal communications linked to the operation were found to be in Simplified Chinese, while the data extracted from the compromised targets appeared in Traditional Chinese, the written form commonly used on government websites in Taiwan, Hong Kong, and Macau.
Attribution and Implications
Dream has not formally attributed the campaign to any specific group. Citing company policy, they only confirmed that they alerted a government in the Asia-Pacific region. However, an individual familiar with the matter identified Taiwan as the target of the attack. Amir Becker, Dream’s chief strategy officer and former head of cyber operations at Israel’s elite Unit 8200, characterized the incident as an unprecedented “end-to-end autonomous attack” on a government entity, emphasizing that the system operated like a coordinated cyber team rather than a simple automated script.
This breach underscores how readily available open-source AI agents can significantly lower the barrier to executing sophisticated, large-scale cyber operations. Tasks that once demanded dedicated teams of skilled human operators working in shifts can now be orchestrated by software capable of mapping networks, stealing credentials, identifying vulnerabilities, and adapting in real-time. This development highlights the urgent need for defenders to develop equally advanced AI systems to detect and neutralize such autonomous campaigns before they can cause widespread damage.
What You Should Do
- Implement robust multi-factor authentication (MFA) across all government accounts and critical infrastructure systems.
- Regularly audit and monitor network traffic for anomalous behavior indicative of AI-driven reconnaissance or lateral movement.
- Conduct frequent vulnerability assessments and penetration tests, specifically focusing on potential weaknesses exploitable by automated tools.
- Train cybersecurity teams on prompt engineering defense strategies to identify and mitigate attempts to bypass AI model safeguards.
- Stay informed about the latest developments in AI-powered attack techniques and integrate AI-driven defense mechanisms into existing security frameworks.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.