Hackers Use Open-Source Hermes AI Agent to Automate Attack on Thai Government Systems

Threat researchers at Hunt.io and security researcher Bob Diachenko uncover evidence that attackers use the open-source Hermes AI agent in fully autonomous "YOLO" mode to automate post-exploitation activity against Thailand's Ministry of Finance. The discovery emerges after the researchers find three exposed web directories on a Hong Kong-hosted server containing approximately 585 files totaling 470 MB. The files include exploit code, web shells, stolen credentials, custom scripts, and detailed logs generated by the Hermes AI agent during the operation.

The recovered files reference specific Ministry of Finance systems by name, hostname, and internal IP address, indicating that attackers target critical infrastructure components such as Hadoop clusters, Apache Ambari, and GlassFish administrative consoles. Scripts also attempt to test authentication against ministry mail servers using hardcoded email addresses and passwords. Hunt.io links the initial server to additional attacker infrastructure through shared TLS certificates with matching fingerprints, revealing a broader network of compromised hosts across Malaysia and other regions.

Despite the compelling evidence uncovered by researchers, Thailand's Ministry of Finance does not officially confirm that a breach occurs, and some artifacts suggest systems are targeted rather than successfully compromised. The incident highlights a growing trend of threat actors abusing open-source AI agents to automate complex attack chains, significantly reducing the time and expertise required for post-exploitation activities. BleepingComputer reaches out to ThaiCERT and the ministry for official comment but receives no immediate response.

Read More at the original source →