Security researchers reported that suspected China-linked operators used open-source AI agent frameworks and multiple large language models to automate cyber intrusions against internet-exposed targets in Taiwan and elsewhere in Asia. Palo Alto Networks Unit 42 said a Chinese-speaking actor tracked as "knaithe" and "KnYuan" used Hermes Agent connected to a DeepSeek model to perform reconnaissance, vulnerability research, and parts of exploitation, while also falling back to manual exploitation when autonomous attempts failed. The actor also tested other Chinese and Western models, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI Codex, indicating active evaluation of AI tooling for offensive operations.
Dream said a related campaign in early July used a platform built from the open-source Hermes and OpenClaw frameworks to carry out what it described as the first observed end-to-end autonomous cyberattack on a government target in Taiwan. According to the firm, the operation ran for four days, deployed up to eight agents in parallel, mapped 21 government systems, compromised at least 85 user accounts, and stole more than 2,500 personnel records before expanding to Taiwan’s nuclear safety agency, at least seven energy companies, government suppliers, and other government systems. Researchers said the activity showed AI agents can continuously adapt attack paths in real time and materially increase the speed and scale of intrusion activity, even without custom malware or highly specialized operators.

Track how attackers are adapting to this technology.
8 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a report describing the Chinese-speaking actor's use of DeepSeek and Hermes Agent to orchestrate vulnerability exploitation and evaluate multiple AI tools for offensive operations. Researchers said the campaign demonstrated a functional end-to-end autonomous offensive workflow despite limited impact.
After the initial government intrusion, the same autonomous campaign reportedly expanded to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems. Dream said the operators ran as many as eight autonomous agents in parallel during the operation.
Over four days in early July, attackers suspected of China links used an AI-agent platform built from Hermes and OpenClaw to map 21 Taiwanese government systems, compromise at least 85 user accounts, and steal more than 2,500 personnel records. Dream described it as the first observed end-to-end autonomous cyberattack against a government target.
Taiwan's National Security Bureau reported in January that the island had faced an average of 2.6 million Chinese cyberattacks per day during 2025. The statistic provided broader context for the later autonomous campaign described by Dream.
Taiwan’s Ministry of Digital Affairs officially confirmed an AI-assisted cyberattack targeting government agencies and described it as an abnormal incident and a world first of its kind. The confirmation concerned the July 2026 intrusion previously reported by Dream, which involved compromised government accounts and data theft.
In the same campaign, Hermes Agent autonomously attempted exploitation of CVE-2026-33017 in Langflow and CVE-2026-21858 and CVE-2025-68613 in n8n Workflow Automation. These attempts failed because target configurations disabled auto_login or required authentication.
During the Asia-focused campaign, the actor manually exploited CVE-2026-3055 on Citrix NetScaler ADC and Gateway and exfiltrated data, confirmed command execution via CVE-2026-39987 on Marimo Notebook, and attempted reverse shells via CVE-2026-34486 on Apache Tomcat and CVE-2026-33824 on Windows IKE Extensions. The actor also cloned but did not execute a proof of concept for CVE-2026-0300 affecting the PAN-OS User-ID Authentication Portal.
A Chinese-speaking threat actor using the aliases "knaithe" and "KnYuan" conducted a campaign against internet-exposed infrastructure in Asia using Hermes Agent with multiple LLMs to automate reconnaissance, vulnerability research, and parts of exploitation. The activity targeted organizations in three countries, including China and Malaysia, and had limited impact without fully compromising intended targets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
13 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcezdnet.fr
Open sourcescworld.com
Open sourceheise.de
Open sourceft.com
Open sourcetomshardware.com
Open sourcedreamgroup.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.