logo

Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

ID: d12d8c4a-d59b-5124-bf7e-3d1110ee9e7c

STIX ID: report--d12d8c4a-d59b-5124-bf7e-3d1110ee9e7c

Feed Name: Hunt.io Blog

Threat Score
88/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Hunt.io discovered three exposed open directories on 43.246.208.207 containing 585 files that reveal an ongoing espionage campaign against Thailand's Ministry of Finance in July 2026: an autonomous AI agent (Hermes) performed unattended network enumeration and LinPEAS-based privilege escalation checks while operators staged a cross-platform Go implant called Hades, webshells, exploit tooling targeting multiple CVEs, mailbox-testing scripts, and hardcoded credentials; TLS certificate pivots and hardcoded C2s link additional Hong Kong/Malaysia infrastructure and provide IOCs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.