Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
ID: d12d8c4a-d59b-5124-bf7e-3d1110ee9e7c
STIX ID: report--d12d8c4a-d59b-5124-bf7e-3d1110ee9e7c
Feed Name: Hunt.io Blog
Hunt.io discovered three exposed open directories on 43.246.208.207 containing 585 files that reveal an ongoing espionage campaign against Thailand's Ministry of Finance in July 2026: an autonomous AI agent (Hermes) performed unattended network enumeration and LinPEAS-based privilege escalation checks while operators staged a cross-platform Go implant called Hades, webshells, exploit tooling targeting multiple CVEs, mailbox-testing scripts, and hardcoded credentials; TLS certificate pivots and hardcoded C2s link additional Hong Kong/Malaysia infrastructure and provide IOCs for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
