{"id":117931,"date":"2026-07-24T16:19:14","date_gmt":"2026-07-24T16:19:14","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/117931\/"},"modified":"2026-07-24T16:19:14","modified_gmt":"2026-07-24T16:19:14","slug":"thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/117931\/","title":{"rendered":"Thailand&#8217;s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged"},"content":{"rendered":"<p>\n\t\t\t\t\t\t\tThailand\u2019s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged\n\t\t\t\t\t\t<\/p>\n<p>\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/user-icon.svg\" alt=\"\"\/> <a href=\"https:\/\/securityaffairs.com\/author\/paganinip\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi Paganini<\/a><br \/>\n\t\t\t\t\t\t\t<img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> July 24, 2026<\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/image-69.png\" alt=\"\"\/><\/p>\n<p>Hunt.io uncovered a cyber-espionage attack on Thailand\u2019s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.<\/p>\n<p class=\"wp-block-paragraph\">Researchers at Hunt.io have uncovered an intrusion targeting Thailand\u2019s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered.<\/p>\n<p><a href=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/07\/image-69.png?ssl=1\" rel=\"nofollow noopener\" target=\"_blank\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"465\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/1784909954_629_image-69.png\" alt=\"\" class=\"wp-image-195958\"  \/><\/a><\/p>\n<p class=\"wp-block-paragraph\">The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand\u2019s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown.<\/p>\n<p class=\"wp-block-paragraph\">One of the most interesting aspects of the operation is the use of Hermes, an open-source autonomous AI agent. Rather than acting as a chatbot, Hermes functioned as an operator assistant capable of executing commands without waiting for approval. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThe attack, targeting Thailand\u2019s Ministry of Finance (MOF) was largely driven by\u00a0<a href=\"https:\/\/hermes-agent.org\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Hermes<\/a>, an autonomous AI agent using \u201cYOLO\u201d mode. Additionally, we identified an unreported Go implant the operator refers to as \u201cHades\u201d.\u201d reads the <a href=\"https:\/\/hunt.io\/blog\/thailand-ministry-finance-targeted-with-hermes-ai-agent\" rel=\"nofollow noopener\" target=\"_blank\">report<\/a> published by Hunt.io \u201cActive session cookie files, deployed webshells, and internal network access indicate the operator was able to compromise multiple systems within the MOF network. How initial access was obtained was not immediately evident from the reviewed documents.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Logs recovered from the exposed directories show the framework running in its so-called YOLO mode, allowing potentially dangerous commands to execute automatically. The recovered logs reveal the agent performing privilege escalation checks, file enumeration, service discovery, and reconnaissance across ministry systems.<\/p>\n<p class=\"wp-block-paragraph\">This isn\u2019t science fiction anymore. It\u2019s simply offensive automation. The only thing missing was someone forgetting to close the directory listing, which, fortunately for defenders, is exactly what happened.<\/p>\n<p class=\"wp-block-paragraph\">The exposed infrastructure also hosted a custom Go-based malware family that researchers named Hades. Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture. Runtime variables also revealed operational safeguards such as configurable working hours and kill dates designed to reduce the implant\u2019s visibility.<\/p>\n<p class=\"wp-block-paragraph\">The investigation paints the picture of an operator that invested considerable effort in understanding the ministry\u2019s internal environment. Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands. <\/p>\n<p class=\"wp-block-paragraph\">\u201cPurpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.\u201d continues the report.<\/p>\n<p class=\"wp-block-paragraph\">Separate tooling focused on Apache Ambari management servers, GlassFish administration consoles, internal web applications, ministry mail services, and document management platforms. Researchers also recovered web shells disguised as legitimate system files together with scripts designed to validate mailbox credentials and reuse active web sessions.<\/p>\n<p class=\"wp-block-paragraph\">Privilege escalation capabilities were already staged inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit (<a href=\"https:\/\/securityaffairs.com\/tag\/cve-2021-4034\" data-type=\"post_tag\" data-id=\"12598\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2021-4034<\/a>), the sudo heap overflow (<a href=\"https:\/\/securityaffairs.com\/tag\/cve-2021-3156\" data-type=\"post_tag\" data-id=\"11572\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2021-3156<\/a>), and the long-standing IIS WebDAV vulnerability (<a href=\"https:\/\/securityaffairs.com\/57513\/hacking\/iis-6-0-zero-day.html\" data-type=\"post\" data-id=\"57513\" rel=\"nofollow noopener\" target=\"_blank\">CVE-2017-7269<\/a>). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems encountered after compromising the target network.<\/p>\n<p class=\"wp-block-paragraph\">Researchers also mapped additional infrastructure by pivoting on TLS certificate characteristics and command-and-control configuration embedded in Hades. That analysis identified multiple related servers hosted in Hong Kong and Malaysia, reinforcing the conclusion that the exposed server was only one component of a broader operational infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">The Hermes logs provide perhaps the clearest evidence of how AI is beginning to reshape offensive operations. Rather than issuing every command manually, the operator delegated routine reconnaissance tasks to the agent, which executed LinPEAS, searched for privilege escalation opportunities, traversed ministry directories, and catalogued files belonging to the Office of the Permanent Secretary for Finance. <\/p>\n<p class=\"wp-block-paragraph\">Hunt.io noted that it found no evidence those documents had been exfiltrated, but the logs show the attackers systematically expanding their visibility inside the environment.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe agent made use of the open-source project\u00a0<a href=\"https:\/\/github.com\/peass-ng\/PEASS-ng\/tree\/master\/linPEAS\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinPEAS<\/a>\u00a0(Linux Privilege Escalation Awesome Script) to further move through the network.\u201d continues the report. \u201cAdditional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance. There is no evidence the files were exfiltrated.\u201d<\/p>\n<p class=\"wp-block-paragraph\">While the researchers stopped short of attributing the operation to a specific threat actor, they assessed with low-to-medium confidence that the operator is Chinese-speaking or closely familiar with the language. That assessment is based on several indicators, including the infrastructure\u2019s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.<\/p>\n<p class=\"wp-block-paragraph\">Beyond the specific victim, this case illustrates how autonomous AI agents are becoming practical offensive tools rather than experimental projects. Hermes wasn\u2019t writing phishing emails or generating malware samples. It was performing the repetitive work that normally consumes an operator\u2019s time, allowing the human behind the keyboard to focus on higher-value decisions while the agent quietly mapped the target\u2019s environment. That\u2019s a capability defenders should expect to encounter far more often in future intrusions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMost of the tools here are ones we have seen before. The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target. Together they describe an operator who invested significant preparation into penetrating a single government target. The method of initial access remains unknown.\u201d concludes the report. \u201cThe server\u2019s history as a ShadowPad controller, active VShell C2, Hong Kong-based infrastructure and Chinese-language indicators, point to a low-to-medium confidence assessment that the actor behind this activity is Chinese-speaking or intimately familiar with the language.\u00a0\u201c<\/p>\n<p class=\"wp-block-paragraph\">Follow me on Twitter:\u00a0<a href=\"https:\/\/twitter.com\/securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">@securityaffairs<\/a>\u00a0and\u00a0<a href=\"https:\/\/www.facebook.com\/sec.affairs\" rel=\"nofollow noopener\" target=\"_blank\">Facebook<\/a>\u00a0and\u00a0<a href=\"https:\/\/infosec.exchange\/@securityaffairs\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/www.linkedin.com\/pub\/pierluigi-paganini\/b\/742\/559\" rel=\"nofollow noopener\" target=\"_blank\">Pierluigi\u00a0Paganini<\/a><\/p>\n<p class=\"wp-block-paragraph\">(<a href=\"http:\/\/securityaffairs.co\/wordpress\/\" rel=\"nofollow noopener\" target=\"_blank\">SecurityAffairs<\/a>\u00a0\u2013\u00a0hacking,\u00a0Hermes AI)<\/p>\n<p>\t\t\t\t\t\t\t\t\t\t\t<script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"Thailand\u2019s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged Pierluigi Paganini July 24,&hellip;\n","protected":false},"author":2,"featured_media":117932,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[24,405,25,7537,315,8066,59815,59816,7512,8067,317,8068,8069,8070,59817],"class_list":["post-117931","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai","tag-ai-agents","tag-artificial-intelligence","tag-artificial-intelligence-agents","tag-hacking","tag-hacking-news","tag-hades-malware","tag-hermes-ai","tag-information-security-news","tag-it-information-security","tag-malware","tag-pierluigi-paganini","tag-security-affairs","tag-security-news","tag-thailands-ministry-of-finance"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117931","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=117931"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/117931\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/117932"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=117931"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=117931"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=117931"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}