Particle.news
Download on the App Store

Hermes AI Agent Used to Automate Probe of Thailand’s Finance Ministry

Researchers disclosed exposed servers and logs showing an operator delegated routine reconnaissance to an automated agent that helped stage a custom implant.

Overview

  • Hunt.io and researcher Bob Diachenko publicly disclosed on July 24 exposed staging directories that contained Hermes agent logs, attack tooling and a previously undocumented Go implant called Hades.
  • Recovered Hermes logs show the agent was run in YOLO mode so it could execute commands without per-command human approval and that it performed scans, privilege-escalation checks and a recursive crawl that read ministry personnel files; investigators found no clear evidence those files were exfiltrated.
  • The intrusion included bespoke scripts targeting the ministry’s Hadoop environment by connecting to HiveServer2 using default or weak authentication and installing a malicious Hive user-defined function to run OS commands and return results over WebHDFS.
  • Artifacts show the human operator had already established access before using the agent, including a hidden web shell and hardcoded mailbox credentials, and related infrastructure tied hosts in Hong Kong and Malaysia with a low-to-medium confidence assessment that the operator was Chinese-speaking.
  • Researchers and vendors published specific detection and mitigation guidance that urges checking HiveServer2 authentication, monitoring web processes connecting to internal Hadoop ports, searching for Hermes result folders and predictable filenames, and patching the listed kernel, sudo, polkit and IIS flaws.