ノーマルビュー

China-Linked Hackers Used AI To Run First-Ever 'Autonomous' Cyberattack On Taiwan

著者: BeauHD
2026年8月13日 05:00

🤖 AI Summary

タイトル:中国関連ハッカーがAIを用いて初めての自主的サイバー攻撃を行ったとされる Taiwanese政府への攻撃

主な内容:
イスラエルのセキュリティ企業Dreamの研究者らは、中国に関連するハッカーたちがAIを使用して初めての端到端の自主的なサイバー攻撃を実行した可能性があると指摘しています。攻撃では少なくとも85人のアカウントが侵害され、2,500以上の人事記録が窃取されました。

この攻撃は7月初旬に4日間続き、最大8つの自主的エージェントが並行して動作したと報告されています。Dreamによると、ハッカーたちは政府システム21系統をスカウトし、ユーザーのアカウントを侵害し人事情報を取り上げました。

攻撃者はさらに台湾の原子力安全関連機関、7つのエネルギー企業、政府サプライヤー、他の政府システムへ活動範囲を拡大しました。

研究者たちは攻撃の証拠として160MBのオンラインアーカイブを見つけ出し、これは2つのオープンソースAIエージェントシステムHermesとOpenClawに基づいていました。これらのツールは容易に入手可能で、多ステップタスクを実行できるように設計されています。

攻撃の最も特筆すべき点は、既存のルートに従う代わりに、状況に応じて攻撃方法を考え出す能力でした。
Researchers at Israeli cybersecurity firm Dream say suspected China-linked hackers used an open-source AI-agent system to conduct what may be the first observed end-to-end autonomous cyberattack against a government. According to the Financial Times (paywalled), the attack compromised at least 85 accounts and resulted in the theft of more than 2,500 personnel records from Taiwanese systems. Tom's Hardware reports: The campaign reportedly ran for four days at the beginning of July and at times deployed as many as eight autonomous agents in parallel. Dream said the system mapped 21 government systems before compromising user accounts and extracting personnel information. The attackers subsequently expanded their activity to Taiwan's nuclear safety agency, at least seven energy companies, government suppliers, and other government systems. Dream says it found the evidence inside a 160-megabyte (160MB) online archive that surfaced during its broader tracking of cyberthreat actors. The archive reportedly held 1,395 files showing that the tool was built on two open-source AI agent systems -- Hermes and OpenClaw -- both of which can be downloaded freely and are designed to let large language models carry out multi-step tasks on their own. Researchers could not determine which underlying model powered the agents, but the data reportedly showed the model's safeguards had been sidestepped by presenting the intrusion as an authorized penetration test rather than a real attack. Of particular concern is that the toolkit for the hack comprised such easily available systems, neither of which was purpose-built for offense. The operators appear to have assembled a capable autonomous tool out of components any developer can pull down and run. What the researchers describe as the tool's most striking feature was its ability to continuously devise attacks on its own, rather than follow a preprogrammed route. The platform continuously assessed available evidence, ranked possible attack paths, and reprioritized them as circumstances changed. When one technique failed, the tool tasked another agent with searching the internet for information and developing an alternative approach.

Read more of this story at Slashdot.

❌