● News

AI Agent Deployed in Automated Attack Against Thai Finance Ministry

July 24, 2026 · snewle
AI Agent Deployed in Automated Attack Against Thai Finance Ministry

Threat actors leveraged the open-source Hermes AI agent operating in unattended mode to automate post-exploitation activities during an alleged intrusion targeting Thailand’s Ministry of Finance. The AI agent attack was discovered after threat intelligence firm Hunt.io and security researcher Bob Diachenko uncovered exposed web directories containing hundreds of files linked to the operation.

Between July 9 and July 13, Hunt.io identified three simultaneously exposed directories on a Hong Kong-hosted server. These directories held 585 files totaling approximately 470 MB, including exploit code, web shells, HTTP tunneling tools, custom scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent. The recovered files referenced Ministry of Finance systems by name, hostname, and internal IP address.

What Evidence Points to Ministry Systems Being Targeted?

Session files, deployed web shells, and evidence of access to internal systems suggest attackers compromised multiple systems within the ministry’s network, according to Hunt.io. Scripts recovered from the exposed directories targeted the ministry’s Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and an administrative web panel. Additional scripts tested authentication against ministry mail servers using hardcoded email addresses and passwords.

Researchers also discovered a PHP web shell allegedly deployed on a Ministry of Finance web server. However, the Ministry of Finance has not confirmed any breach occurred, and some recovered artifacts only demonstrate that certain systems were targeted rather than successfully compromised.

How Did YOLO Mode Enable Automation?

Hermes is an open-source AI agent released in February 2026 that operates as a persistent service capable of remembering information between task sessions. The software includes a setting called YOLO mode, which removes prompts requiring human approval for dangerous commands. Environment information and Hermes output logs recovered from the exposed directories showed the operator had enabled this unattended mode, allowing the agent to execute commands and continue analyzing systems without waiting for human approval.

Five recovered Hermes call logs revealed the agent was instructed to find privilege escalation paths, scan for kernel vulnerabilities, enumerate services, search for SUID and SGID binaries, inspect containers, and traverse file systems. The agent also used a customized version of the LinPEAS privilege-escalation enumeration script to collect information from a Ministry of Finance host.

What Additional Infrastructure Was Uncovered?

Researchers linked the initial server to additional attacker-controlled infrastructure through shared TLS certificates used during the same time period. All certificates shared a JA4X fingerprint, a hash derived from certificate structure. This discovery led to two additional related hosts at IP addresses 118.107.222[.]232 in Malaysia and 202.181.27[.]115 in Hong Kong.

The directories also contained Windows and Linux builds of a previously undocumented Go-based implant the operator called Hades. In one task, Hermes was instructed to recursively search a web directory associated with the Office of Permanent Secretary for Finance, cataloging PDF, DOC, and XLS files including performance assessments and personnel records dating back to 2012. However, Hunt.io found no evidence these files were exfiltrated.

Hunt.io and Diachenko notified ThaiCERT and Thailand’s National Cyber Security Agency on July 15, with both organizations acknowledging receipt that day. The researchers could not determine how attackers initially gained access to the ministry’s systems.

Source: BleepingComputer