A threat actor allegedly used the open-source Hermes AI agent in unattended YOLO mode to automate post-exploitation tasks during an intrusion tied to Thailand’s Ministry of Finance. Hunt.io and Bob Diachenko found exposed directories with web shells, stolen credentials, and logs showing Hermes was used for privilege escalation, enumeration, and internal system traversal. #Hermes #ThailandMinistryofFinance #Huntio #BobDiachenko #Hades
Keypoints
- Hunt.io and Bob Diachenko found exposed attacker directories linked to the alleged ministry intrusion.
- The files included web shells, exploit code, credentials, payloads, and Hermes AI agent logs.
- Recovered artifacts referenced Ministry of Finance systems, internal IPs, and targeted services.
- Hermes was run in YOLO mode to automate privilege escalation, scanning, and system enumeration.
- The Ministry of Finance has not confirmed a breach, and the initial access method remains unknown.