Cybersecurity researchers have uncovered a sophisticated cyber operation in which an attacker used the open-source Hermes AI agent to carry out post-exploitation activities against Thailand’s Ministry of Finance. Instead of manually controlling every step of the attack, the operator allowed the AI agent to work on its own with approval prompts disabled. This discovery highlights how artificial intelligence is beginning to play a larger role in real-world cyberattacks.

The investigation began after researchers found three exposed directories on a server hosted in Hong Kong between July 9 and July 13, 2026. These directories contained nearly 585 files, including exploit tools, web shells, scripts, stolen credentials, and malware used during the attack. The exposed data provided researchers with a rare opportunity to observe an active intrusion while it was still taking place.
One of the biggest findings was that the attacker configured the Hermes AI agent to run in an unattended or “YOLO” mode. In this configuration, the AI automatically executed commands without waiting for user approval, allowing it to perform tasks independently. Logs recovered from the server showed the agent scanning internal systems, searching directories, and collecting information from compromised machines without continuous human involvement.

Researchers found that the AI agent carried out several reconnaissance and privilege escalation activities after gaining access. It searched for files and directories, ran LinPEAS to identify possible privilege escalation paths, and looked for SUID and SGID binaries that could help gain higher system privileges. The recovered logs also showed the agent exploring web directories containing sensitive personnel records inside the ministry’s network.
The investigation also uncovered a previously unknown Go-based malware implant named “Hades.” Researchers found 62 Windows and Linux payloads stored on the staging server, suggesting that the attackers had prepared multiple versions of the malware for different operating systems. According to the analysis, Hades supports encrypted communications and includes several techniques designed to maintain persistence on infected systems.

In addition to the AI agent and malware, researchers discovered web shells, HTTP tunnels, exploit code for multiple vulnerabilities, and scripts containing hardcoded stolen credentials. Evidence also pointed to attempts to target Apache Hadoop infrastructure and internal mail services. While the exact method used for the initial compromise remains unknown, the recovered files indicate that the attackers had already established access to multiple systems inside the ministry’s environment.
The researchers believe this incident represents an important shift in cyber operations because AI agents are now being trusted to perform routine offensive tasks with little or no direct supervision. Instead of issuing every command manually, attackers can allow AI systems to continue reconnaissance, privilege escalation, and data collection on their behalf. This approach reduces the amount of time attackers need to remain actively connected to compromised networks.

Security experts recommend that organizations strengthen network segmentation, closely monitor unusual automated activity, restrict the use of AI agents in sensitive environments, and review system logs for suspicious behavior. They also advise security teams to secure exposed infrastructure, limit administrative privileges, and continuously monitor for indicators of compromise. The incident demonstrates how the combination of AI automation and traditional malware is creating new challenges for defenders across both public and private sectors.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news