Suspected China-Linked Actor Runs Near-Autonomous AI Agent Campaign (Hermes/OpenClaw) Against Taiwan Government, Nuclear Safety Agency, and Energy Sector

Suspected China-Linked Actor Runs Near-Autonomous AI Agent (TL-2026-1998) is a critical-severity advanced persistent threat campaign, first published 2026-08-12. It is linked to a China-nexus actor with medium confidence, affects Government of Taiwan Government agency networks and personnel-records, maps to 13 MITRE ATT&CK / ATLAS techniques (AML.T0054, T1018, T1020), and is covered by 9 detection rules and 9 indicators of compromise.

Key facts for TL-2026-1998

Threat ID
TL-2026-1998
Severity
CRITICAL
Status
ACTIVE
Category
APT
First published
2026-08-12
Last reviewed
2026-08-12
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
government administration, energy, nuclear, critical infrastructure
Target regions
taiwan, East Asia, Asia-Pacific
Detection rules
9
Indicators of compromise
9

Malware and tooling in Suspected China-Linked Actor Runs Near-Autonomous AI Agent

Malware and tooling: Hermes, Hermes, OpenClaw

Israeli cybersecurity firm Dream disclosed what researchers describe as the first observed end-to-end near-autonomous AI cyberattack on a government target: over four days in early July 2026, an attacker assembled from the open-source Hermes and OpenClaw AI agent frameworks deployed up to eight agents in parallel, mapping 21 Taiwanese government systems, compromising at least 85 accounts, and extracting 2,500+ personnel records before expanding into a nuclear safety agency, a government email system, IT supply-chain vendors, and 7+ energy companies. The operator's own documentation, written in Simplified Chinese, gives researchers a high-confidence but unconfirmed China-nexus assessment.

How Suspected China-Linked Actor Runs Near-Autonomous AI Agent works

Dream, an Israeli cyberdefense firm founded by NSO Group co-founder Shalev Hulio, uncovered the campaign while conducting broader threat-tracking work and found an exposed operational archive — roughly 160MB across ~1,395 files — that documented how the operator built an autonomous hacking platform out of two publicly available, legitimate open-source AI agent frameworks: Hermes (an agentic execution framework that can be wired to an arbitrary LLM and given terminal access, internet search, and tool-invocation capability) and OpenClaw (a self-hosted personal AI agent, formerly branded Clawdbot/Moltbot, built for autonomous multi-step task completion). Over a four-day window in early July 2026 the combined platform ran largely on its own, at times running as many as eight agent instances in parallel, mapping 21 Taiwanese government systems and continuously ranking and reprioritizing attack paths.

Dream's CSO, Amir Becker (former head of Israel's Unit 8200 cyber operations), said he had 'never before seen such an end-to-end autonomous attack' on government infrastructure, describing the tool's behavior as resembling a coordinated human red team rather than a single automated script. The archive documented recurring 'Learning Cycles': whenever an attack path was blocked, an agent would independently search public vulnerability databases, GitHub repositories, and security-research publications for new exploitable techniques, then resume the operation with minimal operator input. The platform compromised at least 85 government accounts and extracted more than 2,500 personnel records before expanding beyond the initial 21 systems into Taiwan's nuclear safety agency, a government email system, government IT supply-chain vendors, and at least seven energy-sector companies — scanning the newly identified targets in parallel for misconfigurations and exploitable vulnerabilities.

A key technical finding is how the operator kept the agent framework's own safety controls from blocking the operation: rather than exploiting a flaw in a target system, the operator got the underlying AI model to treat the entire intrusion as an authorized penetration-testing engagement, a jailbreak-by-pretext that let the agents execute clearly unauthorized actions without triggering built-in guardrails. This mirrors a broader dual-use risk that Chinese authorities themselves had already flagged: in March 2026, Beijing restricted OpenClaw at state-run enterprises and government agencies, citing a 'lethal trifecta' of broad private-data access, external communication capability, and exposure to untrusted content, months before OpenClaw resurfaced as a component of this attack platform. Attribution rests on circumstantial but consistent evidence rather than a formal claim: the operator's internal documentation was written in Simplified Chinese while data samples extracted from Taiwan's Traditional-Chinese-language government systems appeared in the same archive; researchers told the Financial Times this makes a China-linked operator likely, though Beijing has not commented and no specific group or individual has been named. Taiwan's Ministry of Digital Affairs declined to comment on the specific incident, citing confidentiality, and said any incidents affecting government agencies or critical infrastructure are handled under standard reporting and response procedures; Taiwan's National Security Bureau separately reported facing an average of roughly 2.6 million Chinese-origin cyberattacks per day in 2025.

This is not an isolated data point: on August 3, 2026, Palo Alto Networks' Unit 42 separately disclosed an unrelated but technically adjacent case in which a Chinese-speaking operator (aliases 'knaithe'/'KnYuan', assessed as based in Zhuhai) wired the DeepSeek model into the same open-source Hermes agent framework and let it autonomously scan and attack 460+ internet-facing systems worldwide via Telegram-issued instructions, confirming three compromises via CVE-2026-3055 in Citrix NetScaler before an agent misconfiguration exposed the attacker's own environment. That campaign targeted opportunistic internet-wide victims rather than a specific government, and was discovered independently by a different firm — it is a distinct threat, not the same operation — but it corroborates that the Hermes framework specifically is being actively weaponized for autonomous offensive operations by more than one operator, and that the AI-orchestrated-attack pattern first surfaced in this Taiwan campaign is part of an emerging class of activity rather than a one-off.

MITRE ATT&CK / ATLAS techniques used in TL-2026-1998

Defense Evasion

AML.T0054 LLM Jailbreak

Discovery

T1018 Remote System Discovery; T1087 Account Discovery

Exfiltration

T1020 Automated Exfiltration

Lateral Movement

T1021 Remote Services

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Collection

T1213 Data from Information Repositories

Credential Access

T1552 Unsecured Credentials

Resource Development

T1588.002 Obtain Capabilities: Tool; T1588.005 Obtain Capabilities: Exploits

Reconnaissance

T1595 Active Scanning; T1595.002 Vulnerability Scanning

Affected products and versions in Suspected China-Linked Actor Runs Near-Autonomous AI Agent

  • Government of Taiwan — Government agency networks and personnel-records systems
    Vulnerable versions: 21 systems mapped; at least 85 accounts compromised; 2,500+ personnel records exfiltrated
  • Taiwan nuclear safety regulatory agency — Agency network (secondary expansion target)
    Vulnerable versions: targeted during campaign expansion; specific compromise scope not publicly disclosed
  • Unnamed government IT supply-chain vendors — Third-party IT services to the Taiwan government
    Vulnerable versions: targeted via trusted-relationship expansion from the core government compromise
  • Multiple (unnamed) — 7+ Taiwan energy-sector companies
    Vulnerable versions: scanned in parallel for misconfigurations/vulnerabilities during expansion phase

Remediation for Suspected China-Linked Actor Runs Near-Autonomous AI Agent

Immediate actions

  • Audit and inventory any self-hosted agentic AI tools (OpenClaw, Hermes, or similar frameworks) present on government and critical-infrastructure networks; treat unmanaged agentic AI deployments as high-risk software supply chain, consistent with China's own March 2026 domestic restriction of OpenClaw over 'lethal trifecta' risk.
  • Force credential resets and MFA re-enrollment across all accounts on the affected Taiwanese government systems and any IT supply-chain vendor accounts with access into those networks.
  • Hunt for anomalous, high-velocity, multi-target reconnaissance consistent with parallel AI-agent orchestration — near-simultaneous scanning/probing of 8+ distinct hosts originating from a single operator context or automation pipeline.
  • Review and tighten network segmentation between core government IT, the nuclear safety regulator, government email infrastructure, and energy-sector partner networks to blunt further trusted-relationship pivoting.

Workarounds

  • Where feasible, block or tightly firewall outbound network access for self-hosted AI agent frameworks (OpenClaw, Hermes, and similar) running on government network segments pending a formal security review.

Longer-term hardening

  • Deploy behavioral/EDR detection tuned to autonomous multi-agent activity signatures (bursty parallel connections, machine-paced request timing, rapid tactic-switching after being blocked) rather than relying solely on static IOC matching.
  • Establish a formal AI-agent usage policy and inventory for government and critical-infrastructure networks, including mandatory jailbreak-resistance and guardrail evaluation before any agentic AI tool is approved for internal or vendor use.
  • Build detection content for 'authorized-pentest' or roleplay-pretext framing appearing in inbound automation traffic, internal LLM API logs, or agent tool-invocation logs to catch jailbreak attempts (MITRE ATLAS AML.T0054).
  • Establish cross-sector threat-sharing between government CERT, the nuclear safety regulator, and the energy-sector ISAC given the confirmed cross-sector expansion pattern demonstrated in this campaign.

Timeline of Suspected China-Linked Actor Runs Near-Autonomous AI Agent

  • China issues internal notices restricting/banning OpenClaw at state-run enterprises and government agencies over a 'lethal trifecta' security risk (broad private-data access, external communication capability, exposure to untrusted content) — months before OpenClaw resurfaces as a component of the attack platform used against Taiwan.
  • Attacker begins a four-day near-autonomous campaign against Taiwanese government networks using a platform built from the Hermes and OpenClaw open-source AI agent frameworks (exact start date not disclosed by Dream; early July 2026 per reporting).
  • Up to eight AI agent instances operate in parallel, mapping 21 Taiwanese government systems and continuously ranking/reprioritizing attack paths, with agents self-researching new techniques via 'Learning Cycles' whenever blocked.
  • Operation expands beyond the initial 21 government systems into Taiwan's nuclear safety agency, a government email system, government IT supply-chain vendors, and 7+ energy-sector companies, scanning each in parallel for misconfigurations.
  • Approximate end of the four-day near-autonomous operation window; at least 85 government accounts compromised and 2,500+ personnel records extracted over the course of the campaign.
  • Dream researchers uncover an exposed ~160MB archive of ~1,395 files documenting the operator's platform and campaign during broader threat-tracking work (exact discovery date not disclosed; disclosed prior to the August 12, 2026 public report).
  • Taiwan's Ministry of Digital Affairs declines to comment on the specific incident, citing confidentiality, and states that incidents affecting government agencies or critical infrastructure are handled per standard reporting and response procedures.
  • Financial Times, CyberScoop, and other outlets publish the first public reporting on Dream's findings; Dream CSO Amir Becker describes it as the first 'end-to-end autonomous attack' he has seen on a government target.

Sources cited for Suspected China-Linked Actor Runs Near-Autonomous AI Agent

Threats related to Suspected China-Linked Actor Runs Near-Autonomous AI Agent

Detection coverage for TL-2026-1998

As of 2026-08-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1998 across Splunk SPL, Microsoft KQL and Sigma, covering 9 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats