logo

Hermes AI agent used to automate attack on Thai Finance Ministry

ID: 45b5b727-d7df-5115-a46a-d21100f6edc0

STIX ID: report--45b5b727-d7df-5115-a46a-d21100f6edc0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Lawrence Abrams

...
...

A Hunt.io and researcher-led investigation uncovered exposed attacker web directories containing exploit code, web shells, credentials, logs, and Windows/Linux builds of a Go-based implant ('Hades') linked to an operation targeting Thailand's Ministry of Finance; logs show the open-source Hermes AI agent was used in unattended YOLO mode to automate post-exploitation tasks such as privilege escalation, service enumeration, and data cataloging, though the ministry has not confirmed a breach.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.