Hermes AI agent used to automate post-exploitation tasks in Thailand Ministry of Finance breach

 

Hermes AI agent used to automate post-exploitation tasks in Thailand Ministry of Finance breach

A threat actor has used the open-source Hermes AI agent to automate post-exploitation tasks during a suspected intrusion involving Thailand's Ministry of Finance.

The activity was discovered by threat intelligence firm Hunt.io and researcher Bob Diachenko after they found exposed web directories on a Hong Kong-based server. The directories contained 585 files totaling about 470 MB, including exploit code, web shells, tunneling tools, custom scripts, stolen credentials, malware payloads, and logs generated by the Hermes AI agent.

According to Hunt.io, the recovered files referenced Ministry of Finance systems by hostname, internal IP address, and service names. Scripts found in the directories targeted several internal technologies, including Hadoop infrastructure, the Apache Ambari management platform, the GlassFish administrative console, and a ministry web administration panel. Researchers also discovered scripts that tested login credentials against ministry email servers.

The researchers found a PHP web shell that they believe had been deployed on a ministry web server. Additional analysis linked the operation to other attacker-controlled servers in Malaysia and Hong Kong through shared TLS certificate fingerprints and command-and-control infrastructure.

The exposed directories also contained Windows and Linux versions of a previously undocumented Go-based malware implant called Hades.

The investigation found that the threat actor used Hermes, an AI agent released in February 2026 that can execute commands, use tools, and maintain memory across multiple task sessions.

Logs recovered from the server showed that Hermes was running in ‘YOLO’ mode, a setting that removes approval prompts for potentially dangerous actions. This allowed the AI agent to carry out commands without constant operator interaction.

The agent performed privilege-escalation checks, scanning for kernel vulnerabilities, enumerating services, searching for SUID and SGID binaries, inspecting containers, and traversing file systems. In one task, Hermes was instructed to run a customized version of the LinPEAS enumeration tool to gather system information from a ministry host.

Another task directed the AI agent to recursively scan a web directory and search PDF, DOC, and XLS files, including personnel records and performance assessments dating back to 2012. Hunt.io said it found no evidence that the documents were exfiltrated.

The findings suggest that Hermes was used as an automation tool, with a human operator supplying objectives and tools. The AI agent carried out routine post-exploitation activities without direct supervision.

Although the recovered artifacts indicate an active intrusion and expanding access within the ministry's network, Thailand's Ministry of Finance has not confirmed a breach. Researchers were also unable to determine the initial access method used by the attackers.

Back to the list