Hermes AI agent used to automate attack on Thai Finance Ministry

A sophisticated cyberattack on Thailand’s Ministry of Finance has been uncovered, with a threat actor using an open-source AI agent called Hermes to automate post-exploitation activity. The attack highlights the growing trend of adversaries leveraging artificial intelligence and machine learning to enhance their capabilities and evade detection.

The breach was discovered by threat intelligence company Hunt.io and security researcher Bob Diachenko, who stumbled upon several exposed web directories containing hundreds of files associated with the operation. These files revealed that the attackers had compromised multiple systems within the ministry’s network, including access to internal services and sensitive data. However, it is unclear whether any actual data was stolen or modified during the attack.

The attackers used a server hosted in Hong Kong as their command center, from which they launched a simultaneous assault on several Ministry of Finance systems. The directories contained exploit code, web shells, HTTP tunneling tools, custom scripts, and logs generated by the Hermes AI agent. The files also referenced Ministry of Finance systems by name, hostname, and internal IP address, and included scripts targeting specific services such as Hadoop infrastructure and Apache Ambari management platform.

One of the most interesting discoveries was a collection of logs showing that the attackers used an AI agent called Hermes to automate parts of the cyberattack. Hermes is an open-source tool released in February 2026 that runs as a persistent service, allowing it to remember information between different task sessions. The software includes a setting known as YOLO (You Only Live Once) mode, which enables unattended operation and removes prompts for human approval.

The researchers were able to recover five Hermes call logs that demonstrate the agent’s capabilities. These logs show that Hermes was used to find vulnerabilities, scan for kernel vulnerabilities, enumerate services, search for SUID and SGID binaries, inspect containers, and traverse file systems. The agent was also instructed to use a customized version of the LinPEAS privilege-escalation enumeration script to collect information from a Ministry of Finance host.

The findings do not indicate that Hermes independently decided to target the ministry. Rather, it appears that the attackers used the AI agent as a tool to automate and streamline their attack. This highlights the growing trend of adversaries leveraging artificial intelligence and machine learning to enhance their capabilities and evade detection.

As this incident demonstrates, the use of AI agents in cyberattacks is becoming increasingly common. This poses significant challenges for security professionals who must now contend with automated attacks that can outpace traditional threat detection methods. In response, organizations should prioritize investing in advanced threat detection and mitigation technologies, as well as training their personnel to identify and respond to AI-driven threats.

For individuals and organizations, this incident serves as a reminder of the importance of maintaining robust security measures and staying vigilant against emerging threats. By doing so, we can better defend ourselves against sophisticated cyberattacks that leverage AI agents like Hermes.


Source: Bleeping Computer — 2026-07-24