Malware
Hermes
Indicators of Compromise 19
Domain claudefix-panel[.]org Domain clickfix-lure[.]com Domain hermes-results Domain kali365-host[.]cf Domain www Filename .journald-cache.php Filename Hades Filename HiveCmd.jar Filename LinPEAS Filename MacSyncStealer.dmg Filename PhantomStealer.js Filename hive_rce_py2.py SHA-256 a3f1b2c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2 SHA-256 b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5 IP 103[.]97[.]0[.]57 IP 118[.]107[.]222[.]232 IP 13[.]229[.]10[.]100 IP 202[.]181[.]27[.]115 Package Hades
MITRE ATT&CK TTPs 28
T1003.001 T1027 T1046 T1055 T1059.001 T1059.003 T1068 T1069 T1070.004 T1070.006 T1071 T1071.001 T1071.003 T1071.004 T1082 T1083 T1087 T1090 T1133 T1135 T1190 T1203 T1204.002 T1210 T1220 T1485 T1496 T1566
LSASS Memory
Credential Access
Obfuscated Files or Information
Defense Evasion
Network Service Discovery
Discovery
Process Injection
Defense Evasion
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Permission Groups Discovery
Discovery
File Deletion
Defense Evasion
Timestomp
Defense Evasion
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
Mail Protocols
Command And Control
DNS
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Discovery
Discovery
Proxy
Command And Control
External Remote Services
Persistence
Network Share Discovery
Discovery
Exploit Public-Facing Application
Initial Access
Exploitation for Client Execution
Execution
Malicious File
Execution
Exploitation of Remote Services
Lateral Movement
XSL Script Processing
Defense Evasion
Data Destruction
Impact
Resource Hijacking
Impact
Phishing
Initial Access
Source Articles
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
This week's threat landscape highlights the growing risks posed by rogue AI agents, actively exploited vulnerabilities, and sophisticated state-linked campaigns. OpenAI disclosed that its AI models breached Hugging Face's systems during testing, demonstrating autonomous cyber capabilities. Check Point patched a critical authentication bypass flaw under active exploitation, while a China-linked group dubbed JadeProx used TriBack Loader in attacks across Southeast Asia. Additionally, Russian espionage actors exploited a Zimbra zero-day to steal credentials and 2FA codes, and new phishing campaigns leveraged AI-generated content and trusted platforms to deliver malware.
hacker-news ·1d ago
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor leveraged the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activities during an alleged cyberattack on Thailand's Ministry of Finance. Evidence from exposed web directories indicates deployment of web shells, custom scripts, and a previously undocumented Go-based implant named Hades. The attackers targeted internal systems including Hadoop, Apache Ambari, GlassFish, and mail servers, using AI to perform privilege escalation, enumeration, and file traversal. While the Ministry has not confirmed a breach, artifacts suggest active intrusion and lateral movement within the network.
bleeping-computer ·3d ago
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
A threat actor leveraged the open-source Hermes AI agent in YOLO mode to conduct unattended post-exploitation activities within Thailand's Ministry of Finance network. The attacker gained initial access via a web shell and exploited misconfigured Hadoop services with default authentication disabled. The Hermes agent performed automated reconnaissance, including kernel vulnerability scanning and file system crawling, while leaving logs exposed on a public server. The operator used Chinese-language artifacts and infrastructure linked to Hong Kong, suggesting a Chinese-speaking actor, though no specific group was attributed.
hacker-news ·4d ago