A Hermes AI agent was used to automate parts of a cyberattack targeting Thailand’s Ministry of Finance, according to research by Hunt.io and security researcher Bob Diachenko. The investigation found evidence of an operator using the agent in unattended “YOLO” mode while staging exploit code, web shells, stolen credentials and a previously unreported Hades implant on exposed infrastructure.
The research team identified three open directories on a Hong Kong-hosted server between July 9 and 13, 2026. The directories contained 585 files totaling about 470 MB of attack code and stolen credentials. The material included tools targeting the ministry’s internal systems, multiple known vulnerabilities and payloads for both Windows and Linux environments.
Hermes AI Agent Ran Unattended Attack Operations
The investigation found logs showing the Hermes AI agent enumerating hosts associated with the Ministry of Finance, traversing files and collecting privilege escalation information from an adjacent system.
Hermes was reportedly operated in YOLO mode, which removes prompts requiring human approval for potentially dangerous commands. Logs recovered from the exposed directories showed the agent using LinPEAS to assess privilege escalation opportunities and enumerate services, files and system information.
Researchers also found evidence that the agent was instructed to search content connected to the Office of the Permanent Secretary for Finance. The material included PDF, DOC and XLS files, along with personnel records. However, the researchers said there was no evidence that these files had been exfiltrated.
The investigation also identified a custom LinPEAS script configured to scan for several 2026 Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-31431 and CVE-2026-43284/CVE-2026-43500.

Hades Implant Found in Windows and Linux Payloads
The 10 July directory contained 62 compiled binaries for Windows and Linux. Analysis of two recovered samples confirmed that they belonged to the same custom malware codebase, which the operator referred to as the Hades implant.
The malware communicates over HTTPS and uses URI paths designed to resemble legitimate web traffic. Its communications are encrypted using AES-256-GCM with a hardcoded key for each build.
The Windows and Linux versions also included different persistence and execution capabilities. The Windows build supported persistence through Registry Run keys and scheduled tasks, while the Linux version used cron jobs. The Windows sample also supported screenshot capture and process hollowing, while both versions included interactive shell, SOCKS proxy and file transfer capabilities.
The recovered samples contained hardcoded command-and-control addresses that researchers said linked the malware to additional infrastructure identified through TLS certificate analysis.
Attackers Targeted Thailand’s Ministry of Finance Infrastructure
Custom scripts found across the exposed directories referenced Thailand’s Ministry of Finance systems, including an administrative web panel, Hadoop infrastructure and the Ambari management platform.
Researchers identified tooling designed to target Apache HiveServer2 using hardcoded credentials and a malicious Hive user-defined function capable of executing commands. Additional scripts targeted an internal GlassFish application server and attempted to deploy web shells.
The investigation also uncovered scripts testing mailbox credentials against ministry mail infrastructure, along with session material associated with an internal administration panel and document management platform.
The attackers had also staged exploit code targeting several known vulnerabilities, including CVE-2021-3156, CVE-2021-4034 and CVE-2017-7269. The research noted that the tooling indicated preparation for privilege escalation and further movement within targeted systems.
Researchers Link Infrastructure to Ongoing Activity
Hunt.io identified three exposed directories hosted on 43.246.208[.]207, an IP address associated with infrastructure in Hong Kong. TLS certificate analysis connected the activity to two additional servers in Malaysia and Hong Kong.
The researchers also identified a separate IP address in the Hermes configuration that appeared to have been used to connect to the staging server.
According to the investigation, the activity appeared to be ongoing when the exposed directories were discovered. The combination of an autonomous AI agent, a cross-platform implant and custom tools targeting specific Ministry of Finance systems indicated significant preparation by the operator.
The initial method used to gain access to the Ministry of Finance network remains unknown. Researchers said they found no evidence confirming that data had left the network.
Thailand’s national CERT and National Cyber Security Agency were notified on July 15, 2026, and acknowledged receipt the same day. The research was published following a standard seven-day disclosure window.
The investigation assessed with low to medium confidence that the actor may be Chinese-speaking or closely familiar with the Chinese language, based on the infrastructure history and language-related indicators. Researchers said they would continue tracking the activity and associated infrastructure.

