# Chinese Hackers Created a 'Near-Autonomous' Attack Using Open-Source AI

> Source: <https://uk.pcmag.com/ai/166678/chinese-hackers-created-a-near-autonomous-attack-using-open-source-ai>
> Published: 2026-08-12 15:06:52+00:00

In a disturbing sign, Chinese hackers used open-source AI to create a “near-autonomous attack” capable of stealing data from government agencies.

The attack was so efficient that it cracked 85 government accounts through password guessing, pilfered thousands of records, and even discovered access vulnerabilities in a government web application, all within about four days, [according](https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia) to Israeli cybersecurity provider Dream.

The attack was launched through a hacker-created software framework that harnesses the free and open-source AI agents Hermes and [OpenClaw](/ai/162926/openclaw-is-the-hot-new-ai-agent-but-is-it-safe-to-use), which can run autonomously on a computer. The framework used at least eight "sub-agents," each dedicated to specific tasks and targets, whether it be vulnerability testing, password-guessing, or "supply chain reconnaissance."

Dream also noted that the [AI agents](/ai/163365/i-want-to-love-ai-agents-but-im-tired-of-their-shortcomings) overrode their own safety guardrails because the instructions were framed as "authorized penetration testing," which amounts to stress testing by a cybersecurity vendor.

The company’s security researchers uncovered the threat last month, discovering “the complete operational workspace of an autonomous AI attack framework that had been actively conducting intrusion campaigns against government entities in Asia.” Specifically, the attack was carried out against government agencies in Taiwan, [according](https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795) to *The Financial Times*, citing an unnamed source.

The creators of the attack were likely from mainland China since the computer code used simplified Chinese Mandarin in the internal status reports. Curiously, the computer code switched to traditional Chinese Mandarin in the “target-facing” analysis, suggesting the attack was intended for Taiwan, where traditional Chinese Mandarin is used.

Dream’s investigation found that the attack stole “2,564+ personnel records,” along with a complete user database. “The attacker didn't stop at primary targets. It expanded the operation to government IT supply chain vendors, a nuclear safety agency, a government email system, and 7+ energy sector companies—scanning them all in parallel for misconfigurations, exposed admin interfaces, and exploitable vulnerabilities,” the company added.

Dream is now warning that the “era of AI-orchestrated” attacks on government infrastructure is here, meaning countries will need to act promptly to secure their systems. “The cost of running a competent attack has collapsed, but the cost of defending against one has not,” it added.

The top AI companies have been offering their latest models to the tech industry and the US government to shore up their defenses, including discovering and patching new flaws. But in a bit of irony, the same cutting-edge models have shown they can go [rogue](/security/166586/the-sandbox-failed-how-openais-experimental-ais-went-rogue-and-attacked-hugging-face) and inadvertently hack other systems, posing a potential risk to any company or government agency that adopts them. OpenAI has [paused](/ai/166630/openai-pauses-work-on-ai-model-over-serious-cybersecurity-risks) the release of its upcoming Astra model due to its gaining “critical cyber capabilities.”
