bleeping-computer · Crawled Jul 24, 2026
Hermes AI agent used to automate attack on Thai Finance Ministry
5 IoCs 2 Malware
Read original article ↗
AI Summary
A threat actor leveraged the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activities during an alleged cyberattack on Thailand's Ministry of Finance. Evidence from exposed web directories indicates deployment of web shells, custom scripts, and a previously undocumented Go-based implant named Hades. The attackers targeted internal systems including Hadoop, Apache Ambari, GlassFish, and mail servers, using AI to perform privilege escalation, enumeration, and file traversal. While the Ministry has not confirmed a breach, artifacts suggest active intrusion and lateral movement within the network.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 5 extracted
MITRE ATT&CK TTPs 34 techniques
T1003.001 LSASS Memory · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1069 Permission Groups Discovery · Discovery T1070.004 File Deletion · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1135 Network Share Discovery · Discovery T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1220 XSL Script Processing · Defense Evasion T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1566 Phishing · Initial Access T1021.003 Distributed Component Object Model · Lateral Movement T1059.007 JavaScript · Execution T1078 Valid Accounts · Defense Evasion T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1554 Compromise Host Software Binary · Persistence T1555 Credentials from Password Stores · Credential Access