On August 12, the internationally renowned cybersecurity company, Dream Security, released its latest investigative report titled “Inside A Multi-Agent AI Framework Used To Compromise Government Entities In Asia.” The report revealed a significant cybersecurity threat where a Chinese-affiliated hacker group is utilizing open-source AI agents to form a multi-agent system, launching highly autonomous network attacks on government institutions in Asia.
According to reports from the Financial Times, the targets continuously attacked by AI agents are government agencies and critical infrastructure in Taiwan. Security experts warn that this marks a pivotal transition in AI-enabled cyberattacks, moving beyond the conceptual stage to “multi-agent autonomous coordination and practical intrusion.”
Unlike traditional AI chatbots, AI agents are goal-driven, requiring only a final objective to autonomously plan and execute tasks. They function more like employees with tools and skills, capable of independently handling complex projects.
In early July, Dream Security’s threat research team discovered an archive folder containing approximately 160MB of data, including 1,395 files, documenting an operational AI autonomous attack framework.
The report highlights that this attack system integrates the popular open-source Hermes and OpenClaw frameworks from the community to construct a complex multi-agent AI architecture:
– Parallel multi-strike: The system can simultaneously dispatch up to 8 alphabetically labeled sub-agents, each with independent attack targets and technical routes during an attack wave.
– Intensive attack waves: Within a few days from July 1 to 4, the system recorded 12 high-intensity attack waves.
– Substantial breach outcomes: The attacks involved stealing government personnel login credentials, data theft from unauthenticated API endpoints, exploiting verification vulnerabilities in government identity verification services, and successfully deploying persistent backdoors in government web applications.
In analyzing the operational logs of the report, Dream Security found that the internal status reports of the system were in Simplified Chinese, while analysis and payload testing against the targets were done in Traditional Chinese. This language feature strongly suggests that the hackers operating the AI system are from mainland China targeting Taiwan using Traditional Chinese.
This AI attack system demonstrates remarkable adaptability. Researchers discovered that the system possesses a rigorous “planning and review loop”:
– Active threat intelligence gathering: The AI autonomously searches CVE vulnerability databases, GitHub code repositories, and the latest cybersecurity research papers to find specific vulnerability exploits applicable to the target government infrastructure.
– Multidimensional filtering and evaluation: The system generates structured reports in each attack cycle based on relevance to the target environment, success rate in breaching defenses, operational priority, and the availability of existing tools for automated classification and filtering of new technologies.
– Error identification and self-abandonment: If an attack path fails or gets intercepted, the AI can recognize its mistake, rapidly adjust strategies, and attempt alternative techniques, showcasing adaptive abilities surpassing traditional automated scripts.
Dream Security’s analysis notes that the rapid evolution of AI-driven network threats is primarily driven by three factors:
– Significant advancement in open-weight models: The Hermes AI agent developed by the open-source AI research institution, Nous Research, reached over 60,000 stars on GitHub within two months of its open-sourcing in February 2026. The OpenClaw project initiated by Austrian engineer Peter Steinberger at the end of 2025 provides robust communication and multitasking capabilities. These powerful open-source models grant anyone with basic computational power access to inference abilities comparable to cutting-edge models.
– Maturation of agentic frameworks: AI frameworks have evolved from mere demonstrations to structures supporting practical combat. Hermes possesses a closed-loop learning capability of “execute-observe-improve,” while OpenClaw functions as a central controller enabling planning loops, parallel dispatch, persistent memory, and post-attack report generation, empowering AI to complete a full kill chain.
– Ineffectiveness of safety guardrails: Internal safety restrictions within the system primarily target compliant regular users. Through prompt engineering, hackers can easily bypass the security safeguards of Hermes and OpenClaw by masking their attacks as “authorized red team simulated vulnerability testing.”
Dream Security emphasizes that nation-state-level network attacks autonomously orchestrated, parallel executed, and dynamically adaptive have transitioned from theoretical to real threats. The pace of their attack evolution significantly outpaces most traditional cybersecurity defenses like fixed IDS/IPS and basic firewalls, rendering past defense systems of governments and enterprises globally vulnerable.
Founded in 2023 by former CEO of Israeli cybersecurity giant NSO Group, Shalev Hulio, former Austrian Chancellor Sebastian Kurz, and cybersecurity expert Gil Dolev, Dream Security aims to protect governments and critical infrastructure using advanced AI technologies. The institution warns that unless governments deeply integrate AI technology into defense, facing such novel multi-agent attacks in the future will become increasingly challenging.
