Hacker deploys AI agent unattended in Thai Finance Ministry breach
This digest was compiled by AI from multiple sources — links to the originals are below.

An attacker used the open-source AI assistant Hermes in YOLO mode to autonomously explore Thailand's Ministry of Finance network after gaining initial access. The agent scanned for root access, crawled personnel records, and ran privilege escalation scripts without human approval. Hunt.io discovered the operation after the operator left logs and 585 files of attack tooling on an exposed web server.
The Breach
The attacker planted a hidden web shell on a ministry web server and used scripts targeting internal Hadoop systems. Stolen mailbox passwords were hardcoded into a mail-testing script. The operator was already inside before the AI agent began its work, according to Hunt.io researcher Bob Diachenko.
AI Agent Role
Hermes, an open-source assistant from Nous Research, was run in YOLO mode, which disables permission prompts for risky commands. The agent autonomously ran LinPEAS to find privilege escalation paths, searched for files with elevated permissions, and crawled a folder of staff personnel records dating back to 2012. No evidence shows the agent discovering new vulnerabilities or choosing targets.
Discovery and Response
Hunt.io found the agent's logs on a web server with directory listing enabled, along with 585 files and 470 MB of attack tooling. Thailand's national CERT and cybersecurity agency were notified on July 15 but had not published any response by July 24. No recovered files indicate data exfiltration.
What's Next
Thailand's cybersecurity agencies are expected to investigate the breach and may issue public statements. It remains unclear how the attacker initially gained access or whether the stolen personnel data was exfiltrated.
1 source
Hacker deploys AI agent unattended in Thai Finance Ministry breach



