A threat actor allegedly used the open-source Hermes AI agent to automate post-exploitation tasks during an attack targeting Thailand’s Ministry of Finance.

Researchers discovered exposed attacker directories containing web shells, stolen credentials, exploit code, custom scripts and activity logs. The evidence points to possible access to several ministry systems, although the ministry has not confirmed a breach.

Exposed infrastructure reveals attack tools

Between 9 and 13 July, researchers identified three publicly exposed directories on a server in Hong Kong. The directories held 585 files totalling roughly 470 MB.

The collection included HTTP tunnelling tools, compiled payloads, web shells, credentials and Hermes AI agent logs. Several files named Ministry of Finance systems, internal IP addresses and hostnames.

The attackers targeted Hadoop infrastructure, Apache Ambari, GlassFish administration services and an internal web panel. They also tested ministry mail-server accounts with hardcoded email addresses and passwords.

Researchers also found a PHP web shell that appears to sit on a ministry web server. Shared TLS certificate characteristics and a command-and-control address in a recovered implant connected the server to further attacker infrastructure.

Hermes AI agent ran in YOLO mode

Hermes is an open-source AI agent that launched in February 2026. It runs as a persistent service, retains information between tasks and can execute commands or use tools for an operator.

Its YOLO mode removes approval prompts for potentially dangerous commands. Recovered environment data and logs show that the operator enabled this unattended setting.

Five Hermes logs show the agent checking for privilege-escalation paths, scanning for kernel vulnerabilities, enumerating services and searching for SUID and SGID binaries. It also inspected containers, traversed file systems and ran a modified LinPEAS enumeration tool against a suspected ministry host.

Sensitive files appeared in a directory search

In one task, the operator told the Hermes AI agent to recursively search a web directory linked to Thailand’s Office of Permanent Secretary for Finance.

The agent catalogued PDF, DOC and XLS files, including personnel records and performance assessments dating back to 2012. Researchers found no evidence that the attackers exfiltrated those files.

The logs do not show Hermes independently choosing the ministry as a target. Instead, an operator supplied its objectives and tools, while YOLO mode let the agent complete routine post-exploitation tasks without repeated human approval.

Authorities received a report

Researchers said the exposed material showed an active operation, with attackers deploying tools and expanding access to internal systems. They could not determine the initial access method.

The researchers notified Thailand’s national cyber authorities on 15 July. Those authorities acknowledged the report that day, but the Ministry of Finance has not publicly confirmed a compromise.

The case shows how autonomous AI agents can accelerate cyberattacks by handling reconnaissance, system enumeration and other repetitive post-exploitation work at scale.


0 responses to “Hermes AI Agent Linked to Alleged Thai Finance Ministry Attack”