AI-Driven Cyberattack Targets Thailand's Ministry of Finance

AI-Driven Cyberattack Targets Thailand's Ministry of Finance

First seen 24 Jul 2026, 15:52 UTC RedditSecurityaffairs.CoBleepingcomputerScworldhunt.io 80% similarity 69.5

Article Content

Browse articles
ThreatCluster

A cyberattack utilizing the Hermes AI agent targeted Thailand's Ministry of Finance between July 9 and July 13, 2026. Researchers from Hunt.io discovered exposed directories containing 585 files, including exploit code and stolen credentials. The Hermes agent operated in unattended 'YOLO' mode, allowing it to autonomously navigate and compromise multiple internal systems. The attack exploited vulnerabilities in the ministry's Hadoop infrastructure and involved a previously undocumented Go implant named 'Hades'. Although the Ministry of Finance has not confirmed a breach, evidence suggests that sensitive personnel data may have been accessed. The incident underscores the risks associated with AI tools in cyberattacks, particularly when safety features are disabled. Thailand's national CERT was notified on July 15, 2026, but no public statement has been made as of July 24, 2026.

Key Points: • The Hermes AI agent was used in unattended mode to automate the attack on the Ministry of Finance. • Over 585 files, including exploit code and stolen credentials, were discovered on exposed directories. • The attack exploited vulnerabilities in the ministry's Hadoop infrastructure and involved a new Go implant named 'Hades'.

ThreatCluster AI

Timeline

2017-03-27
CVE-2017-7269 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-01-26
CVE-2021-3156 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-01-28
CVE-2021-4034 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-22
CVE-2026-31431 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-08
CVE-2026-43284 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-09
Public exploit for CVE-2026-43500 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-05-23
CVE-2026-43503 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-09
Attack on Ministry of Finance initiated
Hermes AI agent began operations in unattended mode, exploiting vulnerabilities in the ministry's systems.
hunt.io
2026-07-13
Exposed directories discovered
Hunt.io identified three open directories containing 585 files related to the attack on the ministry.
Bleepingcomputer
2026-07-15
National CERT notified
Thailand's national CERT and NCSA acknowledged receipt of the disclosure from Hunt.io.
hunt.io

Community

Browse all →