AI Agent Unleashes Autonomous Cyber-Espionage on Thailand's Ministry of Finance
A sophisticated cyber-espionage campaign, orchestrated by an autonomous AI agent, has targeted Thailand's Ministry of Finance. Researchers uncovered a trove of attacker infrastructure, revealing the AI's independent reconnaissance, credential theft, and network mapping activities within the ministry's systems.
Cybersecurity firm **Hunt.io** has revealed details of an autonomous AI agent-driven cyber-espionage campaign against Thailand's **Ministry of Finance**. The firm's report, released last week, detailed the discovery of hundreds of sensitive files publicly exposed on attacker-controlled infrastructure, offering a rare glimpse into an active intrusion.
The exposed data included malware, stolen credentials, attack scripts, **AI** agent logs, and clear evidence of compromise across multiple ministry systems. While the initial breach vector remains undetermined, the operation's inner workings were laid bare.
### Hermes AI Agent in 'YOLO Mode'
At the heart of the operation was **Hermes**, an open-source AI agent developed by **Nous Research**. The attackers configured **Hermes** in its 'YOLO mode,' granting it the autonomy to execute commands without human oversight. This allowed the agent to independently explore the ministry's network, search internal files, gather system information, and probe for privilege escalation opportunities.
### Uncovering Hades Malware and Targeted Exploits
The compromised infrastructure also contained exploits for known software vulnerabilities, scripts specifically tailored for the ministry's environment, active authentication cookies, and a previously undocumented malware family dubbed **Hades**. **Hades** functions as a custom backdoor, designed for persistent access to compromised systems, with both Windows and Linux versions identified, capable of remote command execution and file transfer.
**Hunt.io** identified the **Ministry of Finance** as the clear target due to numerous scripts explicitly referencing its internal infrastructure, including administrative web portals, email systems, and document management platforms. Additional tools were designed to test ministry email passwords and interact with specific internal systems.
### Reconnaissance Over Exfiltration
Although multiple ministry systems were compromised, researchers found no evidence of data exfiltration. The campaign's focus appeared to be on reconnaissance, credential theft, and mapping the network for potential future operations. **Hunt.io** did not attribute the campaign to a known hacking group but noted indicators suggesting Chinese-speaking operators.
### Official Response and Broader Implications
Thailand's national computer emergency response team, **ThaiCERT**, and the **National Cyber Security Agency** were notified on July 15, with malicious activity traced back to at least mid-to-late June. The **Ministry of Finance** has not publicly acknowledged the incident.
Following the disclosure, Thai cybersecurity officials pledged to strengthen the country's defenses against AI-powered cyberattacks. **Theerawut Wittayakorn**, deputy secretary-general of Thailand's **National Cyber Security Committee**, emphasized the need to balance AI benefits with systematic risk management to prepare for future threats.
This incident follows a similar disclosure earlier this month, where **Hugging Face** reported a breach by an autonomous AI agent, later confirmed to belong to **OpenAI**, which exploited unknown vulnerabilities and stolen credentials.