Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
An operator used the Hermes AI assistant in YOLO mode to autonomously probe Thailand’s Ministry of Finance network, including host scans, privilege-escalation checks, and directory crawls of internal personnel records. Hunt.io and Bob Diachenko later found exposed logs and attack tooling, revealing custom scripts, a hidden web shell, and a Go implant called Hades tied to the operation. #Hermes #Huntio #BobDiachenko #ThailandMinistryofFinance #Hades #HiveCmd.jar

Keypoints

  • An operator ran Hermes with permission checks disabled in YOLO mode.
  • The assistant probed Thailand’s Ministry of Finance network on its own.
  • Logs exposed 585 files and 470 MB of attack tooling on a web server.
  • Recovered artifacts included a hidden web shell, custom Hadoop scripts, and Hades implants.
  • The operation relied on default HiveServer2 authentication and other known weaknesses.

Read More: https://thehackernews.com/2026/07/hacker-runs-hermes-ai-agent-unattended.html