INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Thailand's Ministry of Finance Targeted with Hermes AI Agent
| 2026-07-24 12:10 HIGH MEDIUMExecutive Summary AI-generated
The incident involves a targeted cyber-espionage attack on Thailand's Ministry of Finance, with Hermes AI agent and Hades malware being used for reconnaissance and persistence. Researchers at Hunt.io uncovered the intrusion, tracing it to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server containing nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand's Ministry of Finance. The attack was largely driven by Hermes, an autonomous AI agent using "YOLO" mode, which is believed to be Chinese-speaking or intimately familiar with the language.
Technical Mitigations AI-generated
* Regularly review and update software dependencies, plugins, and scripts to prevent exposure to known vulnerabilities.
* Implement least privilege access policies for all systems and applications to limit the attack surface.
* Use secure coding practices when developing custom scripts or tools to prevent privilege escalation and unauthorized command execution.
* Conduct regular security audits and penetration testing to identify potential weaknesses in the system before they can be exploited.
* Keep operating systems, software, and firmware up-to-date with the latest security patches to ensure protection against known vulnerabilities.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShadowPadShadowPad
CVE-2026-43503CVE-2026-43503
CVE-2021-4034CVE-2021-4034
CVE-2026-31431CVE-2026-31431
CVE-2017-7269CVE-2017-7269
CVE-2026-43284CVE-2026-43284
CVE-2021-3156CVE-2021-3156
CVE-2026-43500CVE-2026-43500
Target & Sectors
TH
CN
HK
governmentgovernment
financefinance
Incident Timeline
July 15
Thailand's national CERT was notified on July 15 that Hermes AI agent, running unattended, had been targeted by Hades implant.
Click on any entity below to view its context and source!
target_region
Thailand
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
attribution
CERT
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
attribution
The Hacker News
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
July 23
Threat actors used Hermes AI agent to target the Thailand's Ministry of Finance.
Click on any entity below to view its context and source!
general_metric
5,900 scan events
Hermes's web panel returns a HermesWebUI server header, and a search on that string returned roughly 5,900 scan events over a month, as of Hunt.io's July 23 report, counting sightings rather than distinct machines.
between July 9 and July 13
Threat actors used a Hermes AI agent to target the Ministry of Finance in Thailand.
Click on any entity below to view its context and source!
target_region
Hong Kong
The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server.
July 24
Thailand's national CERT was informed on July 15 that a Hermes AI agent, running unattended, had targeted the agency.
Click on any entity below to view its context and source!
target_region
Thailand
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
attribution
CERT
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
attribution
The Hacker News
Thailand's national CERT and cybersecurity agency were notified on July 15; neither had published anything when The Hacker News checked on July 24.
2026/07/24
Hermes AI agent running unattended was used to target Thailand's Ministry of Finance.
Click on any entity below to view its context and source!
organisation
Thailand’s Ministry of Finance Targeted With
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged.
organisation
Thailand’s Finance Ministry
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.
organisation
Hermes AI
Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.
organisation
MOF
Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF).
data_breach
600 files
Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF).
organisation
YOLO
“The attack, targeting Thailand’s Ministry of Finance (MOF) was largely driven by
Hermes
, an autonomous AI agent using “YOLO” mode.
The mode the operator used, called YOLO, is a documented feature with its own command-line flag.
organisation
Ministry of Finance
Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection.
organisation
Thailand’s Ministry of Finance
Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation.
organisation
the Office of the Permanent
Rather than issuing every command manually, the operator delegated routine reconnaissance tasks to the agent, which executed LinPEAS, searched for privilege escalation opportunities, traversed ministry directories, and catalogued files belonging to the Office of the Permanent Secretary for Finance.
What the agent did
Five files named call_00_*.txt hold the agent's turns: kernel vulnerability scanning against a ministry host, a second LinPEAS run, a sweep for elevated-permission binaries, a filesystem listing, and a recursive crawl of the web root belonging to the Office of the Permanent Secretary.
organisation
PDF
“Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance.
organisation
DOC
“Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance.
organisation
XLS
“Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance.
organisation
the Office of Permanent
“Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance.
organisation
Hacker Runs Hermes AI
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry.
organisation
Post-Exploitation
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry.
organisation
VShell
That assessment is based on several indicators, including the infrastructure’s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.
The same server previously hosted a
ShadowPad
controller and now runs a
VShell
command-and-control listener.
organisation
FOFA
That assessment is based on several indicators, including the infrastructure’s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.
The agent's web interface password contains the Chinese word Leishen, thunder god, and a key for FOFA, a Chinese asset-search service, sits alongside it.
organisation
SSH
The operator's own SSH session into the staging server came from 103.97.0[.]57 in Hong Kong.
infrastructure
Linux
“The agent made use of the open-source project
LinPEAS
(Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report.
LinPEAS
, a standard script that hunts for privilege escalation paths on Linux.
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture.
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
Also staged on the server: a previously undocumented Go implant the operator calls Hades, built for both Windows and Linux in 62 copies.
organisation
Linux Privilege Escalation Awesome Script
“The agent made use of the open-source project
LinPEAS
(Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report.
infrastructure
Windows
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture.
Also staged on the server: a previously undocumented Go implant the operator calls Hades, built for both Windows and Linux in 62 copies.
organisation
CVE-2026-43503
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
organisation
Copy Fail
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
organisation
CVE-2026
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
organisation
DirtyClone
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
organisation
CVE-2017-7269
The directories contained exploit code for well-known vulnerabilities, including PwnKit (
CVE-2021-4034
), the sudo heap overflow (
CVE-2021-3156
), and the long-standing IIS WebDAV vulnerability (
CVE-2017-7269
).
infrastructure
1.9
Patch kernels against all four 2026 flaws above, plus sudo to 1.9.5p2 or later, polkit for CVE-2021-4034, and any remaining IIS 6.0 WebDAV.
infrastructure
6.0
Patch kernels against all four 2026 flaws above, plus sudo to 1.9.5p2 or later, polkit for CVE-2021-4034, and any remaining IIS 6.0 WebDAV.
organisation
Logs
Logs recovered from the exposed directories show the framework running in its so-called YOLO mode, allowing potentially dangerous commands to execute automatically.
organisation
Apache Hadoop
Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands.
organisation
Hive
Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands.
Cloudera warns
that anyone able to install such a function can run arbitrary code as the Hive service account and reach sensitive data.
organisation
MOF Hadoop
“Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.” continues the report.
organisation
Hive UDF
“Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.” continues the report.
organisation
Separate
Separate tooling focused on Apache Ambari management servers, GlassFish administration consoles, internal web applications, ministry mail services, and document management platforms.
organisation
TLS
Researchers also mapped additional infrastructure by pivoting on TLS certificate characteristics and command-and-control configuration embedded in Hades.
organisation
SecurityAffairs
“
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, Hermes AI)
organisation
SQL
A script called hive_rce_py2.py connects to HiveServer2, the SQL front end to that cluster, on an internal machine at port 10000, and sends a password.
organisation
/storage/Counter/nine/.journald-cache.php
This one sat at /storage/Counter/nine/.journald-cache.php and does not appear in a normal directory listing.
organisation
Nous Research
The tool is
Hermes
, an open-source assistant from Nous Research that people install to manage their mail, run chores, and take instructions over Telegram or Slack.
organisation
Telegram
The tool is
Hermes
, an open-source assistant from Nous Research that people install to manage their mail, run chores, and take instructions over Telegram or Slack.
organisation
Slack
The tool is
Hermes
, an open-source assistant from Nous Research that people install to manage their mail, run chores, and take instructions over Telegram or Slack.
organisation
Hadoop
Hunt.io recovered a hidden web shell planted on a ministry web server, scripts written against named internal Hadoop systems, and stolen mailbox passwords hardcoded into a mail-testing script.
organisation
HERMES_YOLO_MODE=1
Hermes offers that setting three ways: a --yolo flag at launch, a /yolo command mid-session, or a HERMES_YOLO_MODE=1 environment variable.
organisation
Office
That folder held Office documents, performance evaluations, and personnel records dating to 2012.
organisation
Dirty Frag
Each hands a local user root where its prerequisites hold, which for Dirty Frag and DirtyClone means CAP_NET_ADMIN.
organisation
Apache
Apache's own documentation
says the default authentication mode is NONE, which accepts whatever password it is given without checking it.
organisation
NONE
Apache's own documentation
says the default authentication mode is NONE, which accepts whatever password it is given without checking it.
organisation
HiveCmd.jar
Once connected, the script installs a malicious Java add-on called HiveCmd.jar as a user-defined function, which lets it run operating-system commands through ordinary database queries and read the results back.
organisation
PHP
Search web roots recursively for PHP files with leading-dot names that imitate system caches.
data_breach
585 files
The operator left the agent's own logs sitting on a web server with directory listing switched on, where threat intelligence firm Hunt.io and researcher Bob Diachenko found them, along with 585 files and 470 MB of attack tooling.
data_breach
470 MB
The operator left the agent's own logs sitting on a web server with directory listing switched on, where threat intelligence firm Hunt.io and researcher Bob Diachenko found them, along with 585 files and 470 MB of attack tooling.
Tactical Metrics
Metrics
data_breach
600
Files
Click for context!
Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF).
Metrics
infrastructure
Linux
Affected Product
“The agent made use of the open-source project
LinPEAS
(Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report.
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture.
LinPEAS
, a standard script that hunts for privilege escalation paths on Linux.
A customized linpeas.sh checked for four 2026 Linux kernel flaws across three families: Copy Fail (CVE-2026-31431),
Dirty Frag
(CVE-2026-43284 and CVE-2026-43500), and
DirtyClone
(CVE-2026-43503).
Also staged on the server: a previously undocumented Go implant the operator calls Hades, built for both Windows and Linux in 62 copies.
Metrics
infrastructure
Windows
Affected Product
Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture.
Also staged on the server: a previously undocumented Go implant the operator calls Hades, built for both Windows and Linux in 62 copies.
Metrics
infrastructure
1.9
Software Version
Patch kernels against all four 2026 flaws above, plus sudo to 1.9.5p2 or later, polkit for CVE-2021-4034, and any remaining IIS 6.0 WebDAV.
Metrics
infrastructure
6.0
Software Version
Patch kernels against all four 2026 flaws above, plus sudo to 1.9.5p2 or later, polkit for CVE-2021-4034, and any remaining IIS 6.0 WebDAV.
Metrics
data_breach
585
Files
The operator left the agent's own logs sitting on a web server with directory listing switched on, where threat intelligence firm Hunt.io and researcher Bob Diachenko found them, along with 585 files and 470 MB of attack tooling.
Metrics
data_breach
470
Mb
The operator left the agent's own logs sitting on a web server with directory listing switched on, where threat intelligence firm Hunt.io and researcher Bob Diachenko found them, along with 585 files and 470 MB of attack tooling.
Intelligence Sources
Security Affairs
2026-07-24
The Hacker News
2026-07-24
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-25T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
44x
organisation
Identified Entity
Thailand’s Ministry of Finance Targeted With
entity
8x
timeline
Temporal Reference
between July 9 and July 13
date
7x
vulnerability
Exploited CVE
CVE-2021-4034
cve
4x
tactic
Cyber Operation Type
Espionage
tactic
4x
source region
Origin Country
Thailand
country
3x
target region
Target Country
Thailand
country
2x
industry
Targeted Sector
Finance
sector
2x
data breach
Files
600
files
2x
infrastructure
Affected Product
Linux
software
2x
attribution
Attributing Entity
CERT
authority
2x
infrastructure
Software Version
1.9
version
Contextual Telemetry
Context Block
7 METRICS
malware
Malware Payload
ShadowPad
tool
general metric
Copies
62
copies
general metric
Scan Events
5,900
scan events
data breach
Mb
470
mb
general metric
Codebase
60
codebase
general metric
Iis
6
iis
general metric
Hits
575
hits
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.