A Multi-Agent AI Framework Used to Compromise Government Entities in Asia

mikeleeorg1 pts0 comments

Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia | | Dream Security Blog

A New Reality - Read the CEO's Post >

Contact UsFill out the form to get in touch with our Expert Team.<br>First Name<br>Last Name<br>Company<br>Job title<br>Phone<br>Email<br>Email<br>Thank you!<br>Your submission has been received!

Oops! Something went wrong while submitting the form.

August 12, 2026<br>Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia<br>Dream Research Labs

Executive Summary<br>AI-enabled offensive operations are now at an inflection point. This is driven by the convergence of three curves:<br>Model capability keeps climbing, and it climbs on open weights that puts frontier-adjacent reasoning in the hands of any operator with hardware<br>Agentic harnesses have matured from demonstrations into operational scaffolding: planning loops, parallel dispatch, persistent memory, and structured after-action reporting that let a model run an intrusion campaign rather than answer questions about one<br>Guardrails, the last practical constraint, hold only against operators who ask honestly.<br>What follows is but one concrete example of what appears to be a near-autonomous attack, running off readily available harnesses and models and aimed at a nation state. Details on the attack were initially shared with the Financial Times.<br>In roughly four days, the agentic attacker produced 1,395 files, 85 cracked credentials, thousands of exfiltrated personnel records, and gained a persistent foothold inside state infrastructure. It spells out one thing loudly - the cost of running a competent attack has collapsed, but the cost of defending against one has not.<br>The Anatomy of a Government AI Attacker<br>In early July 2026, DREAM Lab's Threat Research team uncovered the complete operational workspace of an autonomous AI attack framework that had been actively conducting intrusion campaigns against government entities in Asia. The archive, spanning over 160 megabytes and 1,395 files, reveals a multi-agent AI system that achieved confirmed, real-world compromises against state infrastructure.<br>The framework — built on the Hermes and OpenClaw agents — deploys up to 8 lettered sub-agents in parallel per wave (Agent A through Agent Q observed across the campaign), each assigned to distinct targets and attack techniques. Across 12 documented attack waves conducted over approximately four days (July 1-4, 2026), these agents autonomously cracked government employee credentials, exfiltrated hundreds of personnel records from unauthenticated API endpoints, discovered a signature validation flaw in the government's personal authentication service, and installed persistent backdoors on government web applications.<br>What distinguishes this framework from attack tooling that we've seen before is its operational intelligence:<br>Bayesian prioritization : Posterior probability scoring to continuously rank and reprioritize 14 parallel attack chains, focusing effort on the highest-value targets first<br>Autonomous research : "Learning Cycles" that search vulnerability databases, GitHub repositories, and security publications for new exploitation techniques when existing methods are blocked<br>Feedback loops : Structured after-action reporting that feeds results from each wave back into the planning for the next, enabling the framework to adapt mid-operation without human intervention<br>The framework's own safety guardrails — LLM model refusals — were bypassed by framing all activity as "authorized penetration testing".<br>Linguistic analysis of the operational documentation — which code-switches between Simplified Chinese in internal status reports and Traditional Chinese in target-facing analysis — points to a Chinese-language operator.<br>This report details the framework's architecture, its confirmed impact, and the paradigm shift it represents for defenders: the era of AI-orchestrated, parallel, autonomously adaptive cyber operations against government infrastructure is a reality that will only get more dangerous, with offensive capabilities that outstrip most traditional defensive capabilities.<br>Attack Chain: What the Attacker Successfully Achieved

The Full Attack ChainStep 1: Reconnaissance: Understanding the Target<br>The framework began by automatically mapping the entire government ecosystem. It downloaded and decompiled JavaScript bundles from an Angular-based government portal, extracting every embedded URL, API endpoint, OAuth client ID, and Keycloak configuration object hidden in the compiled code. From this single starting point, it identified 21 connected government systems and mapped the full national SSO architecture — 6 sub-realms, all OIDC endpoints, 2 RSA signing keys, and every supported authentication flow.<br>On one target alone, it discovered 36+ API endpoints spanning account management, user data retrieval, file upload, and administrative functions — many completely unauthenticated. Critically, it found that one of the systems exposed its...

government framework attack agent from against

Related Articles