AI Agents Used in Near-Autonomous Cyberattack on Taiwan

Dream said the campaign used a framework built around the Hermes and OpenClaw agentic AI systems, deploying up to eight autonomous sub-agents at a time across multiple attack waves.

Researchers said the attackers obtained 1,395 files, 85 compromised credentials and thousands of personnel records.

The AI agents reportedly identified vulnerable APIs, discovered a flaw in a government authentication service and installed backdoors on web applications.

According to Dream, the framework could also adapt when attack methods failed, using publicly available information to identify alternative infiltration techniques.

The researchers said safeguards within the AI tools were bypassed by presenting the activity as authorized penetration testing.

The original documentation was reportedly written in Simplified Chinese, although the attackers have not been formally attributed.

Taiwan’s Ministry of Digital Affairs said the investigation found evidence that the attacks originated overseas and involved both conventional operations and AI agents such as OpenClaw.

“The investigation found clear indications that the attacks originated overseas and involved a hybrid approach in which hackers combined conventional operations with AI agents such as OpenClaw,” Taiwan’s Ministry of Digital Affairs said in a Thursday statement.

The hackers’ system was built using open-source AI agents to automate and coordinate much of the intrusion, including reconnaissance, credential attacks and strategizing subsequent attack paths, Dream said.

The Financial Times first reported the case on Wednesday.

The attack comes amid an increasing number of reports of advanced AI models engaging in unauthorized actions, raising concerns about the proliferation of AI-enabled cyberattacks and prompting calls for more government action to regulate AI.