An operator used the Hermes AI assistant in YOLO mode to autonomously probe Thailandβs Ministry of Finance network, including host scans, privilege-escalation checks, and directory crawls of internal personnel records. Hunt.io and Bob Diachenko later found exposed logs and attack tooling, revealing custom scripts, a hidden web shell, and a Go implant called Hades tied to the operation. #Hermes #Huntio #BobDiachenko #ThailandMinistryofFinance #Hades #HiveCmd.jar
Keypoints
- An operator ran Hermes with permission checks disabled in YOLO mode.
- The assistant probed Thailandβs Ministry of Finance network on its own.
- Logs exposed 585 files and 470 MB of attack tooling on a web server.
- Recovered artifacts included a hidden web shell, custom Hadoop scripts, and Hades implants.
- The operation relied on default HiveServer2 authentication and other known weaknesses.
Read More: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html