hacker-news · Crawled Jul 24, 2026

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

6 IoCs 2 Malware 5 CVEs
Read original article ↗

AI Summary

A threat actor leveraged the open-source Hermes AI agent in YOLO mode to conduct unattended post-exploitation activities within Thailand's Ministry of Finance network. The attacker gained initial access via a web shell and exploited misconfigured Hadoop services with default authentication disabled. The Hermes agent performed automated reconnaissance, including kernel vulnerability scanning and file system crawling, while leaving logs exposed on a public server. The operator used Chinese-language artifacts and infrastructure linked to Hong Kong, suggesting a Chinese-speaking actor, though no specific group was attributed.

AI-extracted · verify before operational use

Extracted Entities 7 found

Indicators of Compromise 6 extracted

Type Value Detail
IP 103[.]97[.]0[.]57 Details →
Filename hive_rce_py2.py Details →
Filename .journald-cache.php Details →
Filename HiveCmd.jar Details →
Package Hades Details →
Domain hermes-results Details →

MITRE ATT&CK TTPs 34 techniques

T1003.001 LSASS Memory · Credential Access T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1069 Permission Groups Discovery · Discovery T1070.004 File Deletion · Defense Evasion T1070.006 Timestomp · Defense Evasion T1071 Application Layer Protocol · Command And Control T1071.001 Web Protocols · Command And Control T1071.003 Mail Protocols · Command And Control T1071.004 DNS · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1087 Account Discovery · Discovery T1090 Proxy · Command And Control T1133 External Remote Services · Persistence T1135 Network Share Discovery · Discovery T1190 Exploit Public-Facing Application · Initial Access T1203 Exploitation for Client Execution · Execution T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1220 XSL Script Processing · Defense Evasion T1485 Data Destruction · Impact T1496 Resource Hijacking · Impact T1566 Phishing · Initial Access T1021.003 Distributed Component Object Model · Lateral Movement T1059.007 JavaScript · Execution T1078 Valid Accounts · Defense Evasion T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1554 Compromise Host Software Binary · Persistence T1555 Credentials from Password Stores · Credential Access