Suspected China-Linked Actor Runs Near-Autonomous AI Agent Campaign (Hermes/OpenClaw) Against Taiwan Government, Nuclear Safety Agency, and Energy Sector — Threadlinqs Intelligence
As of 2026-08-12, Suspected China-Linked Actor Runs Near-Autonomous AI Agent Campaign (Hermes/OpenClaw) Against Taiwan Government, Nuclear Safety Agency, and Energy Sector is a critical-severity apt threat attributed to a China (suspected, unconfirmed — linguistic-artifact attribution only)-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 9 indicators of compromise.
Threat ID: TL-2026-1998 · Severity: CRITICAL · Status: ACTIVE · Category: APT
Attribution: China (suspected, unconfirmed — linguistic-artifact attribution only) · ESPIONAGE
Israeli cybersecurity firm Dream disclosed what researchers describe as the first observed end-to-end near-autonomous AI cyberattack on a government target: over four days in early July 2026, an
Dream, an Israeli cyberdefense firm founded by NSO Group co-founder Shalev Hulio, uncovered the campaign while conducting broader threat-tracking work and found an exposed operational archive — roughly 160MB across ~1,395 files — that documented how the operator built an autonomous hacking platform out of two publicly available, legitimate open-source AI agent frameworks: Hermes (an agentic execution framework that can be wired to an arbitrary LLM and given terminal access, internet search, and tool-invocation capability) and OpenClaw (a self-hosted personal AI agent, formerly branded Clawdbot/Moltbot, built for autonomous multi-step task completion). Over a four-day window in early July 2026 the combined platform ran largely on its own, at times running as many as eight agent instances in parallel, mapping 21 Taiwanese government systems and continuously ranking and reprioritizing attack paths.
Dream's CSO, Amir Becker (former head of Israel's Unit 8200 cyber operations), said he had 'never before seen such an end-to-end autonomous attack' on government infrastructure, describing the tool's behavior as resembling a coordinated human red team rather than a single automated script. The archive documented recurring 'Learning Cycles': whenever an attack path was blocked, an agent would independently search public vulnerability databases, GitHub repositories, and security-research publications for new exploitable techniques, then resume the operation with minimal operator input. The platform compromised at least 85 government accounts and extracted more than 2,500 personnel records before expanding beyond the initial 21 systems into Taiwan's nuclear safety agency, a government email system, government IT supply-chain vendors, and at least seven energy-sector companies — scanning the newly identified targets in parallel for misconfigurations and exploitable vulnerabilities.
A key technical finding is how the operator kept the agent framework's own safety controls from blocking the operation: rather than exploiting a flaw in a target system, the operator got the underlying AI model to treat the entire intrusion as an authorized penetration-testing engagement, a jailbreak-by-pretext that let the agents execute clearly unauthorized actions without triggering built-in guardrails. This mirrors a broader dual-use risk that Chinese authorities themselves had already flagged: in March 2026, Beijing restricted OpenClaw at state-run enterprises and government agencies, citing a 'lethal trifecta' of broad private-data access, external communication capability, and exposure to untrusted content, months before OpenClaw resurfaced as a component of this attack platform. Attribution rests on circumstantial but consistent evidence rather than a formal claim: the operator's internal documentation was written in Simplified Chinese while data samples extracted from Taiwan's Traditional-Chinese-language government systems appeared in the same archive; researchers told the Financial Times this makes a China-linked operator likely, though Beijing has not commented and no specific group or individual has been named. Taiwan's Ministry of Digital Affairs declined to comment on the specific incident, citing confidentiality, and said any incidents affecting government agencies or critical infrastructure are handled under standard reporting and response procedures; Taiwan's National Security Bureau separately reported facing an average of roughly 2.6 million Chinese-origin cyberattacks per day in 2025.
This is not an isolated data point: on August 3, 2026, Palo Alto Networks' Unit 42 separately disclosed an unrelated but technically adjacent case in which a Chinese-speaking operator (aliases 'knaithe'/'KnYuan', assessed as based in Zhuhai) wired the DeepSeek model into the same open-source Hermes agent framework and let it autonomously scan and attack 460+ internet-facing systems worldwide via Telegram-issued instructions, confirming three compromises via
Target sectors: government administration, energy, nuclear, critical infrastructure
Target regions: taiwan, East Asia, Asia-Pacific
Timeline
- China issues internal notices restricting/banning OpenClaw at state-run enterprises and government agencies over a 'lethal trifecta' security risk (broad private-data access, external communication capability, exposure to untrusted content) — months before OpenClaw resurfaces as a component of the attack platform used against Taiwan.
- Attacker begins a four-day near-autonomous campaign against Taiwanese government networks using a platform built from the Hermes and OpenClaw open-source AI agent frameworks (exact start date not disclosed by Dream; early July 2026 per reporting).
- Up to eight AI agent instances operate in parallel, mapping 21 Taiwanese government systems and continuously ranking/reprioritizing attack paths, with agents self-researching new techniques via 'Learning Cycles' whenever blocked.
- Operation expands beyond the initial 21 government systems into Taiwan's nuclear safety agency, a government email system, government IT supply-chain vendors, and 7+ energy-sector companies, scanning each in parallel for misconfigurations.
- Approximate end of the four-day near-autonomous operation window; at least 85 government accounts compromised and 2,500+ personnel records extracted over the course of the campaign.
- Dream researchers uncover an exposed ~160MB archive of ~1,395 files documenting the operator's platform and campaign during broader threat-tracking work (exact discovery date not disclosed; disclosed prior to the August 12, 2026 public report).
- Financial Times, CyberScoop, and other outlets publish the first public reporting on Dream's findings; Dream CSO Amir Becker describes it as the first 'end-to-end autonomous attack' he has seen on a government target.
- Taiwan's Ministry of Digital Affairs declines to comment on the specific incident, citing confidentiality, and states that incidents affecting government agencies or critical infrastructure are handled per standard reporting and response procedures.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 9 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, CRITICAL, threat intelligence, cybersecurity, T1595, T1595.002, T1588.002, T1588.005, T1199, T1078, T1552, T1018, T1087, T1021