A sophisticated cyber-espionage operation has targeted Thailand's Ministry of Finance, employing an autonomous AI agent to facilitate portions of the attack. Detailed by threat intelligence firm Hunt.io on July 23, the operation leveraged the Hermes AI agent, an open-source tool, to execute the attack without human intervention. Between July 9 and 13, Hunt.io's platform identified multiple open directories in Hong Kong containing exploit code, web shells, and custom scripts, which were used in the assault.
Hunt.io reported the incident to Thailand's national CERT and National Cyber Security Agency on July 15, with acknowledgment received the same day. The attack infrastructure included post-exploitation tools targeting both Linux and Windows, aiming to expand internal access and escalate privileges. The infrastructure was also identified as having used the Hades malware, a custom implant capable of remote shell access and other malicious activities.
Though the Thai government has not commented, Hunt.io found no evidence of data exfiltration. However, the attack did involve enumeration of sensitive directories. The infrastructure's previous use as a ShadowPad controller and other indicators led Hunt.io to assess, with low-to-medium confidence, that the attackers might be Chinese-speaking.
Hunt.io recommends reviewing HiveServer2 authentication modes, enforcing UDF blocklists, and auditing web roots for PHP files to defend against similar attacks. The attack highlights a trend in AI-powered operations showing poor operational security, as exposed directories led to the discovery of the operation.


