An AI agent known as Hermes was used in an unattended mode to automate post-exploitation activities within Thailand's Ministry of Finance. The agent, which was installed on a rented server, was configured to bypass safety checks and operate independently within the ministry's network. It systematically searched for root access, scanned file systems, and accessed personnel records dating back to 2012.
The operation came to light when Hunt.io and researcher Bob Diachenko discovered the logs left by the agent on a publicly accessible server. Alongside these logs, 585 files and 470 MB of attack tooling were found. The agent, Hermes, is typically used for managing tasks through platforms like Telegram or Slack and is not inherently a hacking tool. However, the operator exploited its YOLO mode, which allows the agent to execute commands without human oversight, a feature that is documented in its command-line options.
The operator had already gained access to the ministry's systems before activating Hermes. Evidence of a web shell and scripts targeting internal systems was found, but there was no indication that data was exfiltrated from the network. The entry point remains unknown. Thailand's national CERT and cybersecurity agency were informed on July 15, yet no public statements have been made as of July 24.
A significant vulnerability exploited was in the Hadoop database service, which by default accepts any password. The operator's custom scripts and password lists were tailored to the ministry's environment, emphasizing the importance of securing default configurations. While Hermes automated processes like privilege escalation checks, the initial breach and script customization required human intervention.
The incident highlights the risks of using AI tools in unauthorized ways and the necessity for organizations to secure their infrastructure against such automated attacks.


