Full Report
In mid-September, Donald Trump announced the creation of a new agency called AI Force — his response to statements from industry leaders about the need to slow the pace of the technology’s development. However, opponents of implementing a voulntary slowdown are fearful of the effects such a step could have on competition with China, whose technology is becoming increasingly popular among hacker groups due to its low cost and weaker security safeguards. Moreover, cyberattacks and other operations using Chinese AI are harder to trace and stop than those involving models by Anthropic or OpenAI, as the companies behind the Chinese models do not report on criminal incidents involving the use of their products. As a result, hackers evade the attention of the authorities, and the number of cyberattacks continues to grow. So far, no concrete countermeasures have been taken to address the problem. In the meantime, the competitiveness of Chinese AI is on the rise, according to Kang Lee, deputy director for technology and geopolitics in Asia at the Institute for Security and Technology (IST).
Analysis Summary
# Threat Actor: Unnamed China-Linked AI Operator
## Attribution & Identity
* **Actor Identification:** Suspected China-linked hackers (as reported by Israeli firm Dream and the Institute for Security and Technology).
* **Aliases:** None specifically named; referred to broadly as "Chinese cyberattacks" or "Chinese hackers."
* **Known Associations:** Linked to Chinese technology ecosystems and utilizing open-source agent frameworks. The activity is described as "espionage on an industrial scale" directed by Beijing.
## Activity Summary
* **Near-Autonomous AI Attack (July 2024):** The first documented near-autonomous cyberattack on a government target. The operation lasted four days and utilized an AI-multi-agent framework to map systems and exfiltrate data.
* **Escalating Intrusion Volume:** The actor is associated with a massive volume of attempts against Taiwan, rising from 2.4 million attempts per day in 2024 to 2.63 million per day in 2025.
## Tactics, Techniques & Procedures
* **AI Agent Orchestration:** Deployment of multi-agent AI frameworks (up to eight agents running simultaneously) to perform real-time hacking strategy adjustments.
* **System Mapping:** Automated mapping of government network systems.
* **Credential Theft:** Compromise of user accounts (85+ accounts in a single campaign).
* **Safeguard Evasion:** Bypassing AI model safety filters by falsely labeling malicious prompts/actions as "authorized penetration tests."
* **Exploitation of Weak Governance:** Utilizing Chinese-developed AI models because the parent companies do not report criminal incidents or provide telemetry to international authorities.
* **Stealth & Attribution Evasion:** Leveraging the "black box" nature of specific AI models to make attacks harder to trace compared to models with strict monitoring (like OpenAI or Anthropic).
## Targeting
* **Sectors:** Government agencies, Nuclear Safety, Energy companies, Technology research.
* **Geography:** Primarily Taiwan; broader interest in the Asia-Pacific region.
* **Victims:** Taiwan National Security Bureau, Taiwan Ministry of Digital Affairs, and unnamed Taiwanese energy/nuclear agencies.
## Tools & Infrastructure
* **Malware & Frameworks:**
* Open-source AI agent frameworks (unnamed).
* "Dark models" – Chinese AI models with low cost and weak security safeguards.
* **Infrastructure:** Usage of multi-agent frameworks to conduct end-to-end autonomous intrusions.
## Implications
* **Strategic Shift:** The transition to autonomous AI attacks marks a "window closing" for traditional defensive measures, as the speed and volume of attacks outpace human-led response capabilities.
* **Geopolitical Advantage:** Chinese AI models are becoming a preferred tool for threat actors due to the lack of reporting requirements by Chinese tech firms, effectively creating a "sanctuary" for cyber operations.
* **Erosion of Attribution:** The use of these models significantly complicates the ability of international authorities to identify and punish the individuals or state entities behind the attacks.
## Mitigations
* **AI-Driven Defense:** Implementation of automated response mechanisms to counter near-autonomous threats.
* **Enhanced Monitoring:** Increased scrutiny of activity originating from or utilizing open-source agent frameworks.
* **Policy Development:** Countermeasures against the proliferation of "unregulated" AI models that lack safety reporting standards.
* **Resilience Planning:** Strengthening nuclear and energy sector infrastructure against automated mapping and exfiltration attempts.