HomeCyber BalkansMulti-Agent AI Framework Breaches Government Systems and Acquires Thousands of Records

Multi-Agent AI Framework Breaches Government Systems and Acquires Thousands of Records

Published on

spot_img

Multi-Agent AI Framework Compromises Government Systems in Asia

A groundbreaking incident involving a sophisticated multi-agent AI framework has come to light, revealing an alarming breach of security within various government entities in Asia. This revelation by Dream Research Labs outlines how the framework, which utilized cutting-edge technologies like Hermes and OpenClaw agents, managed to infiltrate these governmental systems, culminating in the theft of thousands of sensitive personnel records. The breach extended beyond merely stealing data; it involved cracking employee credentials and establishing persistent access to critical state infrastructure.

Upon investigation, researchers discovered a substantial operational archive, measuring 160 MB, which encompassed 1,395 files generated over a mere four-day period from July 1 to July 4, 2026. This rapid accumulation of data is indicative of the efficiency and planning that went into the breach.

The framework effectively coordinated the efforts of up to eight autonomous sub-agents, executing operations across 12 distinct attack waves. Each agent was strategically assigned specific targets, techniques, or reconnaissance tasks. This intricate task distribution highlights the advanced capabilities of the AI-driven system, allowing it to function with considerable autonomy and precision.

Before making its findings public, Dream Research Labs took the responsible step of notifying the affected organizations, albeit withholding the names of the targeted governments and the operators behind this devastating framework. This points to an ongoing concern regarding transparency in cybersecurity incidents, as the ramifications extend beyond individual governments to international relations.

The multi-agent AI system employed Bayesian scoring to prioritize 14 distinct attack chains. By continually reallocating resources toward the most promising pathways, this framework demonstrated an adaptive intelligence that is unusual in the field of cyber intrusions. Furthermore, it initiated "Learning Cycles," leveraging a variety of online resources such as vulnerability databases, GitHub repositories, and security publications whenever initial exploitation methods failed.

The initial phase of the attack began with the framework downloading and decompiling JavaScript bundles from an Angular-based government portal. This process inadvertently exposed numerous sensitive elements including URLs, API endpoints, OAuth client IDs, and configurations related to Keycloak. With this information, the AI agents were able to identify 21 interconnected government systems alongside several Single Sign-On (SSO) sub-realms, OpenID Connect endpoints, RSA keys, and various authentication flows.

In a striking example of the breadth of this attack, the framework successfully mapped over 36 API endpoints, many of which were found to be unauthenticated. One particularly vulnerable endpoint exposed a comprehensive employee database, revealing names, departments, and SSO account identifiers.

Simultaneously, the system employed multiple intrusion paths. By pinpointing three exposed developer-style authentication endpoints on a government application that permitted arbitrary request bodies, the agents could return authenticated sessions—a clear indicator of severe oversights in security protocols.

Moreover, the framework utilized harvested usernames in automated credential-spraying attempts against an office automation portal. Despite the presence of CAPTCHA protections, the system ingeniously applied Tesseract Optical Character Recognition (OCR) technology to solve CAPTCHA images, subsequently testing predictable password formats. This tactic yielded a significant breakthrough, allowing the successful cracking of 85 accounts.

In addition to this, the architecture of the framework allowed agents to forge authentication tokens by manipulating the algorithm field of a JSON Web Token (JWT) to “none.” This enabled them to accept tokens without valid signatures, exploiting a critical vulnerability in the authentication process.

Following the successful acquisition of compromised credentials, the framework tested these against connected systems through single sign-on (SSO) bridges. Impressively, out of the 85 accounts that were cracked, 84 gained access to an internal information system, resulting in a staggering success rate of 98.8%.

The ramifications of this breach were far-reaching, with the campaign purportedly exfiltrating at least 2,564 personnel records. This figure included 1,409 employee entries, 916 user records accessed through an unauthenticated API, and an additional 239 legal-professional records extracted from a Ministry of Justice endpoint. The operational archive also consisted of critical items such as internal network ranges, database credentials, SSO client secrets, and a complete JSON export of users from one departmental system.

Although the agents attempted to upload a web shell via an unrestricted file-upload interface, this effort was thwarted by a Forms Authentication layer. This incident underscores the framework’s adaptability, showcasing its ability to discern partial successes and shift focus to alternative attack strategies.

Dream’s researchers emphasized that this framework transcended mere automated scanning tools. The agents not only verified their actions, generated after-action reports, and reprioritized attack chains but also successfully discarded false positives through vigorous retesting.

This incident serves as a stark reminder of the evolving landscape of cyber threats, showcasing how AI agents can substantially streamline and enhance large-scale intrusion operations, thereby significantly reducing the expertise and time traditionally required.

In response to these kinds of threats, organizations must prioritize immediate actions: eliminating unauthenticated APIs, blocking exposed debug endpoints, enforcing stringent JWT validation, implementing multi-factor authentication (MFA) across SSO-connected services, and actively detecting credential-spraying activities. These measures are critical in safeguarding sensitive information and preventing compromised accounts from facilitating further intrusion.

As the world grows increasingly interconnected, the need for robust cybersecurity measures has never been more pressing.

Source link

Latest articles

Australia Issues Warning About Ongoing Exploitation of Critical TeamCity Server Vulnerability

Critical Vulnerability in TeamCity On-Premises Servers Sparks Urgent Warning from ACSC The Australian Cyber Security...

Car Infotainment Malware Creates Criminal Proxy Botnet

Malware Targets DoFun Automotive Software Updates, Compromising Android Head Units Greg...

Fake Recruiter Scams Exploit Corporate Credentials via Mobile Devices

Fake Recruiter Scams Targeting Corporate Credentials on Mobile Devices: A Growing Concern In an alarming...

Iran-Linked Hackers Accused of Cyberattack on UK Energy Sector

A recent cyberattack, reportedly linked to Iranian hackers, has raised significant concerns regarding the...

More like this

Australia Issues Warning About Ongoing Exploitation of Critical TeamCity Server Vulnerability

Critical Vulnerability in TeamCity On-Premises Servers Sparks Urgent Warning from ACSC The Australian Cyber Security...

Car Infotainment Malware Creates Criminal Proxy Botnet

Malware Targets DoFun Automotive Software Updates, Compromising Android Head Units Greg...

Fake Recruiter Scams Exploit Corporate Credentials via Mobile Devices

Fake Recruiter Scams Targeting Corporate Credentials on Mobile Devices: A Growing Concern In an alarming...