Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence.

Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered.

The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown.

One of the most interesting aspects of the operation is the use of Hermes, an open-source autonomous AI agent. Rather than acting as a chatbot, Hermes functioned as an operator assistant capable of executing commands without waiting for approval.

“The attack, targeting Thailand’s Ministry of Finance (MOF) was largely driven by Hermes, an autonomous AI agent using “YOLO” mode. Additionally, we identified an unreported Go implant the operator refers to as “Hades”.” reads the report published by Hunt.io “Active session cookie files, deployed webshells, and internal network access indicate the operator was able to compromise multiple systems within the MOF network. How initial access was obtained was not immediately evident from the reviewed documents.”

Logs recovered from the exposed directories show the framework running in its so-called YOLO mode, allowing potentially dangerous commands to execute automatically. The recovered logs reveal the agent performing privilege escalation checks, file enumeration, service discovery, and reconnaissance across ministry systems.

This isn’t science fiction anymore. It’s simply offensive automation. The only thing missing was someone forgetting to close the directory listing, which, fortunately for defenders, is exactly what happened.

The exposed infrastructure also hosted a custom Go-based malware family that researchers named Hades. Windows and Linux versions shared the same codebase and supported encrypted command-and-control communications, persistence, interactive shells, file transfers, SOCKS proxying, and, on Windows, process hollowing and screenshot capture. Runtime variables also revealed operational safeguards such as configurable working hours and kill dates designed to reduce the implant’s visibility.

The investigation paints the picture of an operator that invested considerable effort in understanding the ministry’s internal environment. Custom scripts specifically targeted Apache Hadoop infrastructure through HiveServer2, abusing default authentication behavior and malicious Hive user-defined functions to execute operating system commands.

“Purpose-built scripts target MOF Hadoop infrastructure with a HiveServer2 client using hardcoded credentials and a malicious Hive UDF issuing commands and returning output over WebHDFS.” continues the report.

Separate tooling focused on Apache Ambari management servers, GlassFish administration consoles, internal web applications, ministry mail services, and document management platforms. Researchers also recovered web shells disguised as legitimate system files together with scripts designed to validate mailbox credentials and reuse active web sessions.

Privilege escalation capabilities were already staged inside the infrastructure. The directories contained exploit code for well-known vulnerabilities, including PwnKit (CVE-2021-4034), the sudo heap overflow (CVE-2021-3156), and the long-standing IIS WebDAV vulnerability (CVE-2017-7269). The recovered payloads suggest the attackers prepared multiple options depending on the operating systems encountered after compromising the target network.

Researchers also mapped additional infrastructure by pivoting on TLS certificate characteristics and command-and-control configuration embedded in Hades. That analysis identified multiple related servers hosted in Hong Kong and Malaysia, reinforcing the conclusion that the exposed server was only one component of a broader operational infrastructure.

The Hermes logs provide perhaps the clearest evidence of how AI is beginning to reshape offensive operations. Rather than issuing every command manually, the operator delegated routine reconnaissance tasks to the agent, which executed LinPEAS, searched for privilege escalation opportunities, traversed ministry directories, and catalogued files belonging to the Office of the Permanent Secretary for Finance.

Hunt.io noted that it found no evidence those documents had been exfiltrated, but the logs show the attackers systematically expanding their visibility inside the environment.

“The agent made use of the open-source project LinPEAS (Linux Privilege Escalation Awesome Script) to further move through the network.” continues the report. “Additional logs indicate the operator instructed the agent to enumerate a content directory containing PDF, DOC, XLS files, and personnel records associated with the Office of Permanent Secretary for Finance. There is no evidence the files were exfiltrated.”

While the researchers stopped short of attributing the operation to a specific threat actor, they assessed with low-to-medium confidence that the operator is Chinese-speaking or closely familiar with the language. That assessment is based on several indicators, including the infrastructure’s historical association with ShadowPad, the presence of an active VShell command-and-control server, Hong Kong-based hosting, Chinese-language artifacts found during the investigation, and the use of FOFA, a Chinese internet reconnaissance platform.

Beyond the specific victim, this case illustrates how autonomous AI agents are becoming practical offensive tools rather than experimental projects. Hermes wasn’t writing phishing emails or generating malware samples. It was performing the repetitive work that normally consumes an operator’s time, allowing the human behind the keyboard to focus on higher-value decisions while the agent quietly mapped the target’s environment. That’s a capability defenders should expect to encounter far more often in future intrusions.

“Most of the tools here are ones we have seen before. The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target. Together they describe an operator who invested significant preparation into penetrating a single government target. The method of initial access remains unknown.” concludes the report. “The server’s history as a ShadowPad controller, active VShell C2, Hong Kong-based infrastructure and Chinese-language indicators, point to a low-to-medium confidence assessment that the actor behind this activity is Chinese-speaking or intimately familiar with the language. “

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Hermes AI)

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter