Hermes AI Agent: Thailand Ministry Cyberattack Details

1h ago·0:00 listen·Source: The Cyber Express

Summary

A Hermes AI agent was used to automate parts of a cyberattack targeting Thailand’s Ministry of Finance. This is according to research by Hunt.io and security researcher Bob Diachenko. The investigation found evidence of an operator using the agent in an unattended "YOLO" mode. This happened while staging exploit code, web shells, stolen credentials, and a previously unreported Hades implant on exposed infrastructure. The research team identified three open directories on a Hong Kong-hosted server. These directories contained 585 files, totaling about 470 megabytes of attack code and stolen credentials. This material included tools targeting the ministry’s internal systems, multiple known vulnerabilities, and payloads for both Windows and Linux environments. Logs showed the Hermes AI agent enumerating hosts, traversing files, and collecting privilege escalation information. The agent was also instructed to search content connected to the Office of the Permanent Secretary for Finance. This included PDF, DOC, and XLS files, along with personnel records. However, there is no evidence these files were exfiltrated. This matters because it highlights how AI tools are being used in sophisticated cyberattacks.

Read the full article on The Cyber Express

This is an AI-generated audio summary. Always check the original source for complete reporting.

Share
Keep Listening