Hermes AI agent used to automate attack on Thai Finance Ministry

Thai Finance Ministry Under Siege: AI-Powered Hackers in Uncharted Territory

A sophisticated cyberattack on Thailand’s Ministry of Finance has been uncovered, with hackers using an open-source artificial intelligence (AI) agent called Hermes to automate post-exploitation activities. The breach, which occurred between July 9 and 13, exposed several web directories containing hundreds of files associated with the operation.

According to threat intelligence company Hunt.io and security researcher Bob Diachenko, the attackers compromised multiple systems within the ministry’s network, but the Ministry of Finance has not confirmed whether its systems were indeed breached. The researchers discovered evidence of access to internal systems, including session files, deployed web shells, and logs generated by the Hermes AI agent.

The investigation revealed that the hackers used Hermes in unattended “YOLO” mode, which removes prompts requiring human approval for dangerous commands. This allowed the agent to execute tasks autonomously, including scanning for kernel vulnerabilities, enumerating services, and searching file systems. Five recovered Hermes call logs showed the agent was instructed to perform various tasks, such as finding ways to elevate privileges and traverse file systems.

The use of Hermes in this attack marks a new frontier in cyber warfare. This AI agent, released in February 2026, runs as a persistent service and can remember information between task sessions. Its ability to interact with tools and execute commands without human intervention raises concerns about the potential for autonomous hacking operations.

The exposed directories contained exploit code, web shells, HTTP tunneling tools, custom scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent. Some scripts targeted internal services, including the ministry’s Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and an administrative web panel. Other scripts tested authentication against ministry mail servers using hardcoded email addresses and passwords.

The researchers linked the initial server to additional attacker-controlled infrastructure through shared TLS certificates used during the same time period. One of those servers was later linked to the operation through a command-and-control address embedded in a recovered implant.

While the Ministry of Finance has not confirmed whether its systems were breached, the findings suggest that the hackers’ primary goal was to gather sensitive information from internal services and personnel records. The use of Hermes AI agent in this attack highlights the evolving threat landscape, where sophisticated hacking tools are being used to automate attacks and evade detection.

As a result, organizations should be aware of the potential risks associated with unattended AI-powered hacking operations. To mitigate these risks, it’s essential to implement robust security measures, including regular software updates, patch management, and employee education on phishing and social engineering tactics. Additionally, monitoring logs for suspicious activity and implementing AI-powered security tools can help detect and prevent such attacks in the future.

The incident serves as a reminder that cyberattacks are becoming increasingly sophisticated, and organizations must stay vigilant to protect themselves against these evolving threats.


Source: Bleeping Computer — 2026-07-24