Israeli firm Dream has documented what it calls the first known near-autonomous AI attack on a government, one that hit Taiwanese systems and ran on open-source agent frameworks. The evidence sat in a 160 MB archive of 1,395 files that the researchers pieced together this week.
Built on the open-source Hermes and OpenClaw agent frameworks, the tool deployed up to eight sub-agents across 12 attack waves between July 1 and July 4. It mapped 21 government systems, cracked 85 accounts via password spraying, and exfiltrated more than 2,500 personnel records, seven SSO client secrets, and internal database credentials. Operators bypassed model guardrails by framing the work as authorized penetration testing.
The framework ran “learning cycles,” searching vulnerability databases and GitHub for techniques applicable to the target, and reprioritized attack paths as evidence accumulated. When one route failed, it spun up another agent to research a new approach. It then expanded to government IT supply chain vendors, a nuclear safety agency, and at least seven energy companies, scanning them in parallel for misconfigurations.
Dream’s chief strategy officer, a former Unit 8200 operator, said he had never seen this level of autonomy directed at a government, and argued that assumed compromise must now be the baseline posture for every government.
