Researchers and government officials said a China-linked operation used open-source AI agent frameworks to conduct a near-autonomous intrusion campaign against Taiwan government and critical-sector organizations. The activity reportedly combined up to eight sub-agents built on OpenClaw and Hermes to automate reconnaissance, API enumeration, credential theft, vulnerability validation, lateral movement, persistence, and data exfiltration across 12 attack waves. Taiwan’s Ministry of Digital Affairs disclosed abnormal attacks with overseas origins, while reporting tied the campaign to compromises of 85 employee accounts, theft of roughly 2,500 personnel records, and targeting of agencies and suppliers including energy companies, a government email system, IT supply-chain vendors, and the nuclear safety sector.
Separate reporting showed the same AI agent ecosystem is also being abused as a malware and credential-theft supply chain. In the ClawHavoc campaign, attackers poisoned more than 350 OpenClaw ClawHub skills disguised as legitimate tools, then used ClickFix-style lures and a fake AuthTool requirement to push infostealers and steal crypto wallets. Security researchers warned that autonomous agents can pair stolen credentials and session cookies with shared malicious skills, black-market exchanges, and prompt-injection techniques to bypass MFA, move laterally, and even deploy ransomware, turning widely available agent frameworks into a fast-scaling offensive platform and a new software supply-chain risk.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
By August 13, 2026, Taiwan’s Ministry of Digital Affairs had completed its investigation into the July attacks and publicly linked them to a hybrid model combining human hackers with AI agents such as OpenClaw. Separate reporting said Taiwan confirmed the campaign that day.
On August 12, 2026, Dream published research describing a near-autonomous AI-enabled cyberattack against government entities in Asia. The report said attackers bypassed frontier-model guardrails through social engineering and did not need zero-day exploits.
On July 20, 2026, Taiwan’s Ministry of Digital Affairs and the National Institute of Cyber Security issued alerts and launched investigations into abnormal cyberattacks on government agencies. Officials said the activity showed clear characteristics of overseas origins.
Dream said its research team first identified signs of the intrusion on July 2, 2026, during the four-day campaign. The firm later analyzed more than 160 MB of operational data and 1,395 files tied to the activity.
From July 1 to July 4, 2026, a Chinese-language operator used a near-autonomous attack framework built on OpenClaw and Hermes against government targets in Asia-Pacific, likely Taiwan. Dream said the operation used up to eight AI subagents across 12 attack waves for reconnaissance, credential theft, exploitation, exfiltration, and persistence.
On February 1, 2026, Hudson Rock published a report describing OpenClaw, Moltbook, and Molt Road as a "Lethal Trifecta" enabling autonomous intrusion, credential abuse, lateral movement, and ransomware operations.
Trellix identified the ClawHavoc campaign abusing OpenClaw’s ClawHub marketplace with more than 350 poisoned skills disguised as legitimate tools. The campaign used ClickFix-style social engineering and fake "AuthTool" prompts to trick users into installing malware, including NovaStealer v2 on macOS and Linux.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcehudsonrock.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.