Cyber-Espionage Attack on Thailand's Ministry of Finance Using Hermes AI Agent

Cyber-Espionage Attack on Thailand's Ministry of Finance Using Hermes AI Agent

First seen 24 Jul 2026, 15:52 UTC RedditSecurityaffairs.Co 73% similarity 70.5

Article Content

Browse articles
ThreatCluster

A cyber-espionage attack targeting Thailand's Ministry of Finance was uncovered by Hunt.io, revealing the use of the Hermes AI agent and Hades malware for reconnaissance and persistence. The Hermes agent was found running unattended, with logs indicating it executed LinPEAS and accessed the ministry's web root without human intervention. The attack was detected through exposed staging servers on a Hong Kong server, which were accessible from July 9 to 13. This incident highlights vulnerabilities in the ministry's cybersecurity posture and the potential for significant data compromise. The current status of the attack is under investigation, with researchers analyzing the extent of the breach and its implications.

Key Points: • Thailand's Ministry of Finance was targeted in a cyber-espionage attack using Hermes AI. • The Hermes agent operated without human oversight, indicating a high level of automation. • The attack was detected through exposed servers, raising concerns about cybersecurity practices.

ThreatCluster AI

Timeline

2026-07-09
Exposed staging servers discovered
Three open directories on a Hong Kong server were found, revealing the Hermes AI agent's activity.
Reddit
2026-07-13
Hermes AI agent activity logged
Logs showed the Hermes agent executing LinPEAS and accessing the Ministry's web root unattended.
Reddit
2026-07-24
Attack confirmed by Hunt.io
Hunt.io reported the cyber-espionage operation, detailing the use of Hermes AI and Hades malware.
Securityaffairs.Co

Community

Browse all →