Skip to content
Tech News
← Back to articles

Hermes AI agent used to automate attack on Thai Finance Ministry

read original more articles
Why This Matters

The use of Hermes AI by threat actors to automate attacks on Thailand's Ministry of Finance highlights the growing sophistication of cyber threats leveraging AI tools for post-exploitation activities. This incident underscores the importance for organizations to strengthen their cybersecurity defenses against AI-enabled attacks, which can rapidly and automatically target multiple internal systems. As AI tools become more accessible, both industry and consumers must prioritize proactive security measures to mitigate potential damages from such automated threats.

Key Takeaways

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance.

The activity was uncovered by threat intelligence company Hunt.io and security researcher Bob Diachenko after they discovered several exposed web directories containing hundreds of files associated with the operation.

Hunt.io says session files, deployed web shells, and evidence of access to internal systems indicate that the attackers compromised multiple systems within the ministry's network.

However, the Ministry of Finance has not confirmed that its systems were breached, and some of the recovered artifacts only show that particular systems were targeted rather than successfully compromised.

BleepingComputer contacted Thailand's Ministry of Finance and ThaiCERT to confirm the reported attack and will update this story if we receive a response.

Attack infrastructure exposed online

Between July 9 and July 13, Hunt.io discovered three simultaneously exposed directories on a server hosted in Hong Kong.

The directories contained 585 files totaling approximately 470 MB, including exploit code, web shells, HTTP tunneling tools, custom scripts, stolen credentials, compiled payloads, and logs generated by the Hermes AI agent.

The recovered files referenced Ministry of Finance systems by name, hostname, and internal IP address, and included scripts targeting internal services.

Some scripts targeted the ministry's Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and an administrative web panel. Other scripts tested authentication against ministry mail servers using hardcoded email addresses and passwords.

... continue reading