Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
ID: dd384a57-c22b-548d-9494-57f9b3018ab7
STIX ID: report--dd384a57-c22b-548d-9494-57f9b3018ab7
Feed Name: The Hacker News
An operator deployed the open-source Hermes AI assistant with its YOLO (no human-approval) mode on a rented server and used it to automate reconnaissance and exploitation against Thailand's Ministry of Finance; investigators (Hunt.io and Bob Diachenko) found exposed agent logs, web shells, custom tooling (including a Go implant named Hades), and evidence the agent crawled personnel records and attempted kernel and service exploits. The intrusion leveraged a Hadoop/HiveServer2 instance with default NONE authentication to install a malicious Hive UDF, included scripts targeting recent 2026 kernel flaws and other legacy vulnerabilities, and left identifiable indicators (HermesWebUI header, hermes-results folders, staging IPs), though no confirmed data exfiltration was observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
