
Open-Source Hermes AI Agent Used to Automate Thai Ministry Cyberattack
Exposed attacker infrastructure revealed how the Hermes AI agent in YOLO mode automated post-exploitation tasks, including privilege escalation and system mapping, against Thailand’s Ministry of Finance.
Threat intelligence firm Hunt.io and security researcher Bob Diachenko have uncovered evidence that a threat actor leveraged the open-source Hermes AI agent to automate post-exploitation activities during an apparent breach of Thailand's Ministry of Finance. The operation came to light after several exposed web directories were found online, containing hundreds of files that mapped out the attacker's tools and methods.
The directories, hosted on a server in Hong Kong and accessible between July 9 and July 13, held 585 files totaling approximately 470 MB. Among them were exploit code, various web shells, HTTP tunneling utilities, custom scripts, stolen credentials, and logs generated by the Hermes AI agent. The logs revealed that the operator had enabled Hermes' 'YOLO' mode, a setting that bypasses human approval prompts and allows the agent to execute dangerous commands autonomously.
Recovered call logs show Hermes was tasked with privilege escalation, searching for kernel vulnerabilities, enumerating services, locating SUID/SGID binaries, inspecting containers, and traversing file systems. In one instance, the agent was instructed to run a customized version of the LinPEAS enumeration script to gather system details. It also navigated a web directory belonging to the Office of Permanent Secretary for Finance, cataloging documents such as performance assessments and personnel records, though no exfiltration was confirmed.
The attackers appeared to have deep knowledge of the ministry's internal network, with files referencing systems by name, IP address, and hostname. Scripts targeted the ministry's Hadoop infrastructure, Apache Ambari management platform, GlassFish administrative console, and internal mail servers, often using hardcoded credentials. A PHP web shell was identified on a ministry web server, and the researchers also discovered a previously unknown Go-based implant dubbed 'Hades' with both Windows and Linux builds.
While it is unclear how initial access was obtained, the exposed artifacts show an intrusion in progress, with tools staged and internal access expanding. The use of an AI agent like Hermes highlights a growing trend: earlier this month, the JadePuffer ransomware operation used a similar agent to automate an entire attack chain from reconnaissance to encryption, and OpenAI reported its models autonomously hacking during a benchmark test.
For website owners and hosting providers, this incident underscores the critical need for robust, continuously monitored environments. Web shells and automated scripts can be uploaded in seconds, and without proactive detection, they provide persistent backdoors. AEU Hosting's managed WordPress platform is secured end to end, with file integrity monitoring and malware scanning that help identify and block such threats before they escalate—an essential safeguard in an era where adversaries are arming AI for automation.