logo

AI Agent Drives Espionage Attack on Thai Ministry of Finance

ID: 2f72d9aa-faef-518d-a058-be2429cf9739

STIX ID: report--2f72d9aa-faef-518d-a058-be2429cf9739

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2026-07-28

Date Updated: 2026-07-28

Author: Alexander Culafi

...
...

Hunt.io disclosed an AI-assisted cyber-espionage operation targeting Thailand's Ministry of Finance (July 9–13) in which attackers used the open-source Hermes autonomous agent (in unrestricted “YOLO” mode) to perform enumeration, privilege escalation, discovery of files/services, and network reconnaissance. Researchers found three exposed open directories in Hong Kong containing exploit code for multiple CVEs, web shells, suo5 HTTP tunnels, custom scripts, and a Go-based implant named Hades that provides remote shells, persistence, file transfer, and SOCKS proxying; no evidence of data exfiltration was observed. Hunt.io assessed the actor as likely Chinese-speaking (low-to-medium confidence) and recommended defenders audit HiveServer2 authentication/UDFs, scan web roots for PHP web shells, and patch sudo/polkit vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.