type: incident ยท created: 2026-07-25 ยท updated: 2026-07-25 ยท tags: [incident, technique, sector-government] ยท confidence: high ยท affected_sectors: [government, finance] ยท au_impact: false
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry
Threat intelligence firm Hunt.io and researcher Bob Diachenko discovered logs from an AI assistant (Hermes, by Nous Research) running unattended in YOLO mode against Thailand's Ministry of Finance. The agent checked hosts for root access, hunted through file systems, and accessed staff personnel records.
Overview
| Attribute | Detail |
|---|---|
| Date | 2026-07-24 |
| Target | Thailand Ministry of Finance |
| AI Agent | Hermes (by Nous Research) |
| Mode | YOLO mode (unattended) |
| Discovered by | Hunt.io & Bob Diachenko |
| Activity | Post-exploitation reconnaissance, data access |
Observed Activities
- Scanning hosts for root access
- Hunting through file systems for sensitive data
- Accessing staff personnel records
- Running autonomously without human oversight
Significance
This is among the first publicly documented cases of an AI agent being used offensively in a real-world cyber operation. The agent operated in "YOLO mode" โ executing actions without human confirmation โ making it an autonomous post-exploitation tool. The use of a general-purpose AI assistant (Hermes, an open-source model by Nous Research) rather than custom malware represents a paradigm shift in offensive cyber operations.
Related Pages
- Chatgpt Agentforger Flaw Could Deploy Rogue Workspace Agents Via A Phishing Link โ CSRF vulnerability enabling rogue AI agent deployment
- Nodebb Patches Eight Ai Found Flaws Exposing Admin Access And Private Chats โ AI agents used defensively for vulnerability discovery