Researchers say attackers targeted and likely breached multiple systems at Thailand's Ministry of Finance, then used the open-source Hermes AI agent in unattended mode to automate parts of the intrusion. Hunt.io found exposed attacker directories containing 585 files, including stolen credentials, web shells, custom scripts, and logs showing Hermes was used for privilege-escalation checks, service enumeration, filesystem traversal, and Linux post-exploitation; the ministry had not confirmed the breach at publication.
Why it matters: This matters because it is a real-world example of AI being used to speed up hands-on intrusion work inside a government network, which could lower the skill and time needed for follow-on attacks. Government defenders and anyone running exposed admin tools should review logs for web-shell activity, credential misuse, and suspicious enumeration, and treat exposed attacker artifacts as indicators of compromise.
2026.08.14
40% relevant
This article adds broader context that Hermes- and OpenClaw-based agentic attack frameworks were also used in early July against Taiwanese government and energy targets, reinforcing the real-world use of autonomous AI agents in intrusions but describing a different victim set and operation.
2026.08.12
92% relevant
This appears to be the same Dream-reported near-autonomous campaign using open-source Hermes and OpenClaw AI agents, but this article adds the concrete victim identification of Taiwan, plus details that the operation expanded from government systems to a nuclear safety agency, IT supply-chain vendors, and at least seven energy companies, with 85 accounts and 2,500+ personnel records compromised.
Lawrence Abrams
2026.07.24
100% relevant
This article establishes a distinct story centered on the suspected Ministry of Finance intrusion and the attackers' documented use of Hermes in YOLO mode to automate post-exploitation.
← Back to all stories