Multi-Agent Framework Compromises Taiwanese Government Systems
- Autonomous Agents
- Credential & Identity Theft
- Data Exfiltration
In early July 2026, an unknown Chinese-language operator used a multi-agent framework built on Hermes and OpenClaw against government systems that subsequent public reporting identified as Taiwanese. Dream Research Labs recovered a 160 MB operational workspace containing 1,395 files documenting 12 attack waves conducted from July 1 through July 4. Taiwan's Ministry of Digital Affairs separately confirmed detecting abnormal attacks during July involving a hybrid of human operation and OpenClaw-assisted activity. The agentic AI framework coordinated up to eight specialized sub-agents concurrently across reconnaissance, authentication attacks, API testing, vulnerability research, and exploitation. A probabilistic decision engine ranked findings and 14 candidate attack paths, allocated additional testing to promising results, discarded invalidated paths, and used after-action reports to redirect subsequent activity. Starting from an internet-facing government portal, the framework decompiled client-side application bundles and mapped connected systems, identity infrastructure, and exposed APIs. It obtained access through exposed debug endpoints, unsigned JWT acceptance, and password spraying based on personnel identifiers collected from unauthenticated APIs. Tesseract OCR automated CAPTCHA solving, reportedly helping compromise 85 accounts, 84 of which authenticated to another government system through an SSO bridge without additional MFA or user confirmation. Dream Research Labs reported the extraction of more than 2,564 personnel records, a complete user-database export, SSO configuration and client information, database credentials, and internal network ranges.