Within the alleged breach of the Thai Ministry of Finance, menace actors used the open supply Hermes AI agent in unattended “YOLO” mode to automate post-exploitation actions.
The exercise was uncovered by menace intelligence agency Hunt.io and safety researcher Bob Diachenko after they found a number of public net directories containing lots of of information associated to the operation.
Hunt.io says session information, deployed net shells, and proof of entry to inner techniques point out the attackers have compromised a number of techniques inside the division’s community.
Nonetheless, the Treasury Division has not confirmed that its techniques had been compromised, and among the recovered artifacts solely point out that particular techniques had been focused moderately than efficiently compromised.
BleepingComputer contacted the Thai Ministry of Finance and ThaiCERT to verify the reported assault. We are going to replace this text if we obtain a response.
Assault infrastructure uncovered on-line
Between July ninth and July thirteenth, Hunt.io found three directories uncovered concurrently on a server hosted in Hong Kong.
The listing contained 585 information totaling roughly 470 MB, together with exploit code, net shells, HTTP tunneling instruments, customized scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent.
The recovered information referenced Treasury techniques by title, hostname, and inner IP handle and contained scripts concentrating on inner providers.
A few of the scripts focused the division’s Hadoop infrastructure, Apache Ambari administration platform, GlassFish administration console, and administration net panel. Different scripts examined authentication to the division’s mail server utilizing hard-coded e-mail addresses and passwords.
Hunt.io additionally found a PHP net shell that was allegedly deployed on the Treasury Division’s net servers.
Researchers linked the primary server to further attacker-controlled infrastructure by means of a shared TLS certificates used throughout the identical interval.
“Along with a standard title, all these certificates share a JA4X fingerprint, which is a hash derived from the construction of the certificates itself moderately than its contents,” Hunt’s report explains.
“Querying that hash together with the www widespread title in HuntSQL returned two extra associated hosts: 118.107.222(.)232 (The Gigabit, Malaysia) and 202.181.27(.)115 (Converged Communications Restricted, Hong Kong).”
One among these servers was later linked to the operation by means of a command and management handle embedded in a recovered implant.
This listing additionally contained Home windows and Linux builds of a beforehand undocumented Go-based implant that the operators referred to as Hades.
However the extra fascinating discovery was a group of logs displaying that the attackers used the AI agent “Hermes” to automate among the cyberattacks in opposition to the ministry.
Hermes in YOLO mode
Hermes is an open supply AI agent launched in February 2026 that runs as a persistent service and might bear in mind info throughout totally different process periods.
AI brokers can work together with instruments and execute instructions whereas performing duties supplied by operators.
The software program features a setting often called YOLO mode that removes prompts asking customers to approve harmful instructions.
Researchers had been in a position to recuperate environmental info and Hermise output logs from uncovered directories that point out that operators have enabled this unattended mode. This enables the agent to execute instructions and proceed analyzing the system with out ready for human approval at every step.
5 recovered Hermise name logs present that the agent was used to search out methods to raise privileges, scan kernel vulnerabilities, enumerate providers, search for SUID and SGID binaries, examine containers, traverse file techniques, and extra.
Hermes was additionally instructed to make use of a custom-made model of the LinPEAS privilege escalation enumeration script to gather info from Treasury hosts.
In one other process, the operator instructed Hermes to recursively search net directories associated to the Workplace of the Undersecretary of Finance.
The company created a catalog of PDF, DOC, and XLS information containing efficiency evaluations and personnel data courting again to 2012. Nonetheless, Hunt mentioned he discovered no proof that these information had been compromised.
The findings don’t point out that Mr. Hermes independently determined to focus on the division.
As an alternative, the revealed logs present the operator offering targets and instruments to the agent, whereas in YOLO mode it was in a position to carry out routine post-exploit instructions with out fixed monitoring.
In keeping with Hunt.io, the recovered artifacts depict an lively intrusion through which instruments had been planted and expanded entry to inner techniques. Nonetheless, researchers had been unable to find out how the attackers gained entry within the first place.
The corporate and Diatchenko notified ThaiCERT and the Nationwide Cyber Safety Authority of Thailand on July 15. Each organizations acknowledged receiving notices on the identical day, the report mentioned.
This Hermes exercise is the most recent instance of autonomous AI brokers being utilized in cyberattacks.
Earlier this month, the JadePuffer ransomware operation used AI brokers to automate the complete intrusion, together with reconnaissance, credential theft, lateral motion, privilege escalation, and information encryption.
Autonomous brokers could cause breaches in the actual world, even unintentionally.
OpenAI lately revealed that its mannequin autonomously hacked Hugging Face throughout a cybersecurity benchmark check and exploited a zero-day vulnerability to flee from the sandbox testing atmosphere and entry the web.
They then used stolen credentials and extra vulnerabilities to infiltrate Hugging Face’s manufacturing techniques.

Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remaining strikes invisibly by means of the atmosphere.
Picus’ whitepaper reveals the way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
