Cybersecurity researchers have uncovered a sophisticated cyber-espionage campaign targeting Thailand’s Ministry of Finance. The investigation revealed that attackers used an open-source AI assistant called Hermes to automate many post-exploitation activities after gaining access to the ministry’s systems. Researchers discovered the operation while analyzing exposed attacker infrastructure that accidentally revealed valuable evidence about the ongoing attack.

thailand-ministry-of-finance-ai-cyberattack

The attack was identified by Hunt.io researchers together with security researcher Bob Diachenko after they found three publicly exposed directories hosted on a server in Hong Kong. These directories contained hundreds of files, including exploit tools, web shells, stolen credentials, custom scripts, malware samples, and detailed logs showing how the attackers operated inside the compromised environment.

One of the most notable findings was the use of the Hermes AI agent in its unattended “YOLO” mode. In this configuration, the AI assistant can execute commands without asking for human approval, allowing it to perform tasks automatically. Researchers stressed that Hermes itself is not malicious and has no security flaw, but the attackers intentionally misused its automation capabilities during the intrusion.

give seo title with

The recovered AI logs showed that Hermes was used to scan internal systems, move through files, collect system information, and identify opportunities for privilege escalation. Investigators also found evidence that the attackers had deployed web shells, gathered active session cookies, and accessed multiple internal systems belonging to the Ministry of Finance, indicating that the compromise had progressed beyond the initial intrusion stage.

Researchers also discovered a previously undocumented malware implant named “Hades,” which was written in Go and designed to run on both Windows and Linux systems. The malware was capable of maintaining persistence, transferring files, acting as a proxy, and supporting command-and-control communications. The attackers hosted dozens of payloads that could be delivered depending on the victim’s operating system.

cybersecurity-operations-center-ai-espionage

Further analysis showed that the threat actors had prepared scripts targeting Apache Hadoop infrastructure within the ministry. The exposed files included hardcoded credentials, malicious Hive components, and code designed to execute commands through WebHDFS. Investigators also found several well-known exploit tools prepared for vulnerabilities such as PwnKit, Baron Samedit, and the IIS WebDAV flaw, suggesting the attackers were equipped to exploit multiple systems if needed.

Although researchers confirmed that multiple ministry systems had been compromised, they could not determine exactly how the attackers first gained access. Based on infrastructure history, technical indicators, and other evidence, the researchers assessed with low-to-moderate confidence that the operation may have been carried out by a Chinese-speaking or Sinophone threat actor. However, they emphasized that this attribution is not definitive.

digital-forensics-cyber-espionage-investigation

The incident highlights how cybercriminals are increasingly using AI agents to automate routine hacking tasks, making espionage operations faster and more efficient. Researchers notified Thailand’s national CERT and the National Cyber Security Agency before publicly releasing their findings. Security experts recommend closely monitoring AI-assisted activity, protecting exposed services, patching known vulnerabilities, and strengthening endpoint detection to identify unusual automated behavior inside networks.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news