Skip to content

Threat Actor Uses Open-Source AI Agent Hermes in Unattended Mode to Breach Thailand’s Ministry of Finance

A threat actor has been found to have used an open-source AI agent, Hermes, in unattended mode to automate parts of a cyberattack against Thailand’s Ministry of Finance. The attack was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation.

**Timeline of Discovery: July 9-13, 2023**

Between July 9 and July 13, Hunt.io discovered three simultaneously exposed directories on a server hosted in Hong Kong. The directories contained 585 files totaling approximately 470 MB, including exploit code, web shells, HTTP tunneling tools, custom scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent.

**Files Recovered: Evidence of Ministry of Finance Systems Targeting**

The recovered files referenced Ministry of Finance systems by name, hostname, and internal IP address. They included scripts targeting internal services such as Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and an administrative web panel. Other scripts tested authentication against ministry mail servers using hardcoded email addresses and passwords.

**PHP Web Shell Deployment on Ministry of Finance Server**

Hunt.io also found a PHP web shell that it says had been deployed on a Ministry of Finance web server. The researchers linked the initial server to additional attacker-controlled infrastructure by shared TLS certificates used during the same time period.

**Use of AI Agent in Cyberattacks: A Growing Concern**

The use of an AI agent in this attack is not surprising, as autonomous agents can be used to conduct cyberattacks and cause real-world breaches. Earlier this month, the JadePuffer ransomware operation used an AI agent to automate an entire intrusion, including reconnaissance, credential theft, lateral movement, privilege escalation, and data encryption.

**Hermes AI Agent: A Persistent Service with Unattended Mode**

The Hermes AI agent was released in February 2026 as an open-source tool that runs as a persistent service and can remember information between different task sessions. The software includes a setting known as YOLO mode, which removes prompts that would require a person to approve dangerous commands. In this case, the operator had enabled unattended mode, allowing the agent to execute commands and continue analyzing systems without waiting for human approval at each step.

**Hermes Call Logs: Evidence of System Scanning and Privilege Elevation**

The recovered Hermes call logs show the agent was used to find a way to elevate privileges, scan for kernel vulnerabilities, enumerate services, search for SUID and SGID binaries, inspect containers, and traverse file systems. The operator instructed Hermes to use a customized version of the LinPEAS privilege-escalation enumeration script to collect information from a Ministry of Finance host.

**Incident Highlights Risks of AI Agent Use in Cyberattacks**

The incident highlights the potential risks of using AI agents in cyberattacks and the importance of monitoring for suspicious activity. It also underscores the need for organizations to be vigilant in detecting and responding to threats, as autonomous agents can cause real-world breaches even if unintentional.

**Conclusion: Threat Actor’s Initial Access Unknown**

The findings do not indicate that Hermes independently decided to target the ministry, but they do show an active intrusion in which tools had been staged and access to internal systems was expanding. However, the researchers could not determine how the attackers initially gained access.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *