Eigen RadarAI
Analysis

AI agents entered the intrusion chain

Two investigations trace AI tools from reconnaissance and credential theft into later attack stages, confronting defenders with a threat that can move faster and operate more continuously.

Artificial Intelligence··Midday
In a sunlit substation room, teal and amber fiber cables meet at a metal junction and branch into blank control housings.

A twelve-wave agent attack on Taiwan

In the first four days of July, an attack framework built on the Hermes and OpenClaw AI agents was aimed at targets in Taiwan. According to The Register, the near-autonomous system ran twelve waves, deploying up to eight sub-agents, each with its own targets and techniques. The attackers broke into a government website, then compromised a government email system, the country's nuclear safety agency, IT supply-chain vendors and at least seven energy companies. As they moved across the network they found and exploited misconfigurations and flaws while stealing data and credentials. Operators linked to China are suspected; no state attribution has been established. Tom Kellermann, vice-president for AI security at TrendAI, calls the situation a clear and present danger. Brett Leatherman, assistant director of the FBI's Cyber Division, says his teams are focused on attacks aimed at critical infrastructure. The same report notes there is no evidence that AI was used in the attacks on water utilities in the United States, a distinction that keeps the Taiwan agent case from being read as a universal pattern.[1]

Models that sit inside the intrusion lifecycle

Gambit Security's report AI Across the Intrusion Lifecycle examines three unrelated groups of attackers. According to the text by Eyal Sela, director of threat intelligence, and Nir Varon, a cyber threat researcher, the models do more than write malware: as an intrusion unfolds they produce scripts fitted to the system in front of them, prioritise stolen business data and help decide the next step. Across the three investigations, attackers are described using models at different stages of an intrusion: generating scripts fitted to the environment they meet, developing exploitation tools, sorting out valuable business information, handling IT and operations tasks, and reworking commands based on the output returned by compromised systems. The report sets this apart from earlier discussion of AI-assisted crime, which centred on phishing messages, malware generation and a lower barrier for inexperienced attackers. The shared line is that the model no longer stops at pre-attack preparation; it enters the daily workflow of the break-in itself.[2]

Speed and continuity pressure on defenders

Read together, the two sources push the threat picture past one-off malware generation. The Taiwan case shows that agent sub-processes can advance wave by wave and near-autonomously; the Gambit investigations show that models also enter the command loop after reconnaissance, credential theft and data sorting. For defenders, the result is that monitoring designed for a slower human tempo comes under pressure on both speed and continuity. Critical infrastructure and government systems sit at the centre of the case The Register reports, while the Gambit report describes the same pressure spreading into the workflow of private intrusions. The China-link suspicion and the absence of evidence for AI in United States water-utility attacks keep attribution and scope as separate questions. Still, the shared warning is clear: once AI tools sit in the middle of the intrusion chain, response time and human oversight capacity are tested directly.[1], [2]

References

  1. News sourceThe RegisterA 12-wave break-in on Taiwan ran on the Hermes and OpenClaw agents↩1↩2
  2. News sourceUnite.AIThree separate intruders folded AI into the daily work of a break-in↩1↩2