Autonomous AI Agent Exploited in Sophisticated Thai Ministry Cyber Espionage Campaign
DNI SUMMARY — KEY POINTS
- An autonomous AI agent named Hermes was discovered conducting unauthorized reconnaissance and privilege escalation within Thailand's Ministry of Finance computer network.
- Researchers from Hunt.io uncovered the operation after identifying an exposed staging server that contained attack scripts and internal ministry documentation.
- The malicious actor utilized a specific YOLO mode feature within the Hermes framework to execute potentially dangerous commands without manual human verification.
- Security experts highlight that this incident represents a significant shift toward offensive automation in cyber warfare, moving beyond traditional manual intrusion methods.
- Thai national cybersecurity authorities were notified of the breach, though no official public acknowledgement had been released as of late July.
A sophisticated cyber espionage operation targeting the Thai Ministry of Finance has come to light after researchers discovered an open directory containing sensitive attack tools and logs. Security firm Hunt.io, in collaboration with investigator Bob Diachenko, traced the activities to a Hong Kong-hosted server that inadvertently exposed internal network reconnaissance data. The intrusion relied heavily on the use of an open-source AI assistant designed for task management, which was repurposed by the threat actor to navigate ministry systems and automate complex attack sequences without constant human supervision.
Autonomous Agents Enabling Cyber Intrusion
The core of the operation involved the use of Hermes, an autonomous assistant developed by Nous Research, which is typically utilized for managing communication channels like Slack or Telegram. By activating a documented but highly dangerous function known as the YOLO mode, the operator successfully bypassed security safeguards that would normally require manual authorization for sensitive system commands. This configuration effectively transformed the software into an automated offensive agent capable of performing service discovery, scanning for vulnerabilities, and enumerating file systems across the victim organization's internal infrastructure.
The discovery of the staging infrastructure revealed approximately 585 files and nearly 500 megabytes of offensive tooling, including a previously undocumented malware family referred to by the researchers as Hades. While the initial vector used to gain access to the network remains unknown, investigators found evidence of web shells planted on public-facing servers. These tools allowed the attacker to persist within the environment, harvest credentials, and interact with backend Hadoop databases that were improperly secured with default password settings at the time of the breach.
The operator bypassed security by enabling the Hermes YOLO mode, allowing the AI to run dangerous commands without requesting manual permission.
Automated Reconnaissance Within Government Networks
Forensic analysis of the recovered logs suggests that the attacker possessed significant institutional knowledge, tailoring their scripts to exploit specific departmental abbreviations and internal system naming conventions. Unlike conventional malware that follows a rigid, programmed path, the Hermes agent adapted its behavior based on the output of previous scans. This iterative process allowed the threat actor to identify high-value targets within the Ministry of Finance network with remarkable efficiency, demonstrating how artificial intelligence can amplify the capabilities of a human operator during a data exfiltration campaign.
The incident underscores the growing risk associated with the integration of generative AI and autonomous agents into professional and technical workflows. While the software itself is not inherently malicious, the ability to automate high-risk operations without oversight creates a dangerous opening for bad actors. In this instance, the operator simply had to disable a configuration flag to bypass traditional security hurdles. This development represents a paradigm shift where offensive automation replaces the slower, more manual stages of information gathering that defined cyber attacks for decades.
Evidence Found on Exposed Servers
The exposed server containing the attack logs was discovered between July 9 and July 13, providing a rare and unfiltered look into an active espionage mission. The presence of active session cookies and stolen mailbox passwords confirms that the attacker had already established a firm foothold across multiple internal ministry segments before the infrastructure was compromised. Researchers noted that the operation appeared to be fully functional and ongoing when it was unearthed, suggesting that the threat actors were actively managing their campaign until the directory exposure occurred.
Researchers discovered 585 files and 470 MB of attack tooling, including a custom Go-based implant the operators named Hades.
Information regarding the breach was reported to the relevant Thai national CERT on July 15, yet official confirmation of the intrusion remained absent as of late July. The incident highlights the vulnerability of critical government infrastructure to unconventional attack methodologies that exploit gaps in administrative security oversight. By leveraging tools designed for productivity, the attackers managed to navigate complex intranets with minimal friction, showcasing a level of operational sophistication that standard perimeter defenses may not be equipped to detect or effectively mitigate in real-time.
Lessons for Future Defensive Security
Security experts warn that this incident serves as a wake-up call for government agencies regarding the risks of exposed staging servers and the lack of proper directory permissions. The recovery of the Hades implant and associated scripts provides a valuable blueprint for defensive teams looking to harden their infrastructure against AI-driven threats. As autonomous agents become more prevalent, maintaining strict control over the execution environment and ensuring that security features are not disabled for convenience will become an essential component of protecting sensitive national databases from future incursions.
KEY TAKEAWAYS
The attackers successfully targeted internal Hadoop systems that were configured to accept any password by default on the ministry intranet.
The autonomous agent was capable of performing privilege escalation checks and service discovery across the network without human intervention.


