logo

Hermes AI Agent Used to Automate Attack on Thai Finance Ministry

ID: 352fd5fc-11c5-5a47-8f4a-86cf5efc756c

STIX ID: report--352fd5fc-11c5-5a47-8f4a-86cf5efc756c

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

...
...

An attacker repurposed the open-source Hermes AI agent by enabling its unattended "YOLO" mode to autonomously perform post-exploitation activity against Thailand's Ministry of Finance, including kernel CVE scanning, LinPEAS enumeration, SUID/GUID probing, full filesystem listings, and a webroot crawl that exposed office documents and personnel records; researchers discovered the campaign after the attacker left detailed operation logs and ~470 MB of tooling exposed on a publicly-accessible server, yielding a near-complete playbook of the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.