INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Thailand's Ministry of Finance Targeted with Hermes AI Agent

| 2026-07-24 12:10 HIGH MEDIUM
Executive Summary AI-generated
The incident involves a targeted cyber-espionage attack on Thailand's Ministry of Finance, with Hermes AI agent and Hades malware being used for reconnaissance and persistence. Researchers at Hunt.io uncovered the intrusion, tracing it to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server containing nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand's Ministry of Finance. The attack was largely driven by Hermes, an autonomous AI agent using "YOLO" mode, which is believed to be Chinese-speaking or intimately familiar with the language.
Technical Mitigations AI-generated
* Regularly review and update software dependencies, plugins, and scripts to prevent exposure to known vulnerabilities. * Implement least privilege access policies for all systems and applications to limit the attack surface. * Use secure coding practices when developing custom scripts or tools to prevent privilege escalation and unauthorized command execution. * Conduct regular security audits and penetration testing to identify potential weaknesses in the system before they can be exploited. * Keep operating systems, software, and firmware up-to-date with the latest security patches to ensure protection against known vulnerabilities.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad CVE-2026-43503CVE-2026-43503 CVE-2021-4034CVE-2021-4034 CVE-2026-31431CVE-2026-31431 CVE-2017-7269CVE-2017-7269 CVE-2026-43284CVE-2026-43284 CVE-2021-3156CVE-2021-3156 CVE-2026-43500CVE-2026-43500
Target & Sectors
TH CN HK
governmentgovernment financefinance
Incident Timeline
‎July 15
Thailand's national CERT was notified on July 15 that Hermes AI agent, running unattended, had been targeted by Hades implant.
target_region Thailand
attribution CERT
attribution The Hacker News
‎July 23
Threat actors used Hermes AI agent to target the Thailand's Ministry of Finance.
general_metric 5,900 scan events
‎between July 9 and July 13
Threat actors used a Hermes AI agent to target the Ministry of Finance in Thailand.
target_region Hong Kong
‎July 24
Thailand's national CERT was informed on July 15 that a Hermes AI agent, running unattended, had targeted the agency.
target_region Thailand
attribution CERT
attribution The Hacker News
‎2026/07/24
Hermes AI agent running unattended was used to target Thailand's Ministry of Finance.
organisation Thailand’s Ministry of Finance Targeted With
organisation Thailand’s Finance Ministry
organisation Hermes AI
organisation MOF
data_breach 600 files
organisation YOLO
organisation Ministry of Finance
organisation Thailand’s Ministry of Finance
organisation the Office of the Permanent
organisation PDF
organisation DOC
organisation XLS
organisation the Office of Permanent
organisation Hacker Runs Hermes AI
organisation Post-Exploitation
organisation VShell
organisation FOFA
organisation SSH
infrastructure Linux
organisation Linux Privilege Escalation Awesome Script
infrastructure Windows
organisation CVE-2026-43503
organisation Copy Fail
organisation CVE-2026
organisation DirtyClone
organisation CVE-2017-7269
infrastructure 1.9
infrastructure 6.0
organisation Logs
organisation Apache Hadoop
organisation Hive
organisation MOF Hadoop
organisation Hive UDF
organisation Separate
organisation TLS
organisation SecurityAffairs
organisation SQL
organisation /storage/Counter/nine/.journald-cache.php
organisation Nous Research
organisation Telegram
organisation Slack
organisation Hadoop
organisation HERMES_YOLO_MODE=1
organisation Office
organisation Dirty Frag
organisation Apache
organisation NONE
organisation HiveCmd.jar
organisation PHP
data_breach 585 files
data_breach 470 MB
Tactical Metrics
Metrics
data_breach
600
Files
Metrics
infrastructure
‎Linux
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎1.9
Software Version
Metrics
infrastructure
‎6.0
Software Version
Metrics
data_breach
585
Files
Metrics
data_breach
470
Mb