cd /news/ai-agents/a-hacker-turned-deepseek-into-an-aut… · home topics ai-agents article
[ARTICLE · art-83586] src=startupfortune.com ↗ pub= topic=ai-agents verified=true sentiment=↓ negative

A Hacker Turned DeepSeek Into an Autonomous Weapon Against 460 Servers

Hunt.io and security researcher Bob Diachenko discovered an exposed server in Hong Kong that revealed an active intrusion attempt against Thailand's Ministry of Finance between July 9 and July 13, 2026, using the open-source AI agent Hermes in unattended YOLO mode. The server exposed 585 files (about 470 MB) including exploit code, web shells, stolen credentials, and payloads, with logs showing the agent enumerating hosts and searching for files, including personnel records dating back to 2012. Hunt.io also identified 62 compiled payloads, including a previously unreported Go implant called Hades, indicating multiple systems were compromised, though no confirmed data exfiltration was found.

read4 min views1 publishedAug 2, 2026
A Hacker Turned DeepSeek Into an Autonomous Weapon Against 460 Servers
Image: Startupfortune (auto-discovered)

Public reporting does not support the claim that Unit 42 found a DeepSeek-driven agent attacking 460 servers. The verified story is narrower, and still serious: Hunt.io and Bob Diachenko found Hermes running unattended during an alleged intrusion targeting Thailand's Ministry of Finance.

The cleaner version of this story is also the more useful one. According to research published by Hunt.io on July 23, 2026, and conducted with security researcher Bob Diachenko, an exposed server in Hong Kong gave researchers a look at an active operation against Thailand's Ministry of Finance between July 9 and July 13. The server did not just hold a stray script or two. It exposed 585 files, about 470 MB in all, including exploit code, web shells, stolen credentials, attack logs, and payloads for Windows and Linux.

That is enough detail to stop treating agentic AI abuse as a conference-slide risk. You can now point to a real server, a real ministry, real dates, and files left open on the internet. The mistake was not subtle. The operator left the working room visible.

Hunt.io said the attacker used Hermes, an open-source AI agent, in unattended YOLO mode. Hermes can run commands and interact with tools while working through objectives from an operator. YOLO mode removes approval prompts for commands that would normally ask a human to stop and confirm. That feature has legitimate uses in trusted automation. In this setting, it meant the agent could keep enumerating systems and checking paths without waiting for a person at every step.

The Agent Was Doing The Routine Work #

The recovered Hermes logs showed the agent enumerating ministry hosts, traversing files, checking services, inspecting containers, and searching for SUID and SGID binaries. LinPEAS handled the privilege-escalation reconnaissance. In one task, according to Hunt.io, the operator directed Hermes to search a web directory tied to Thailand's Office of the Permanent Secretary for Finance. The agent cataloged PDF, DOC, and XLS files, including personnel and assessment records dating back to 2012.

No confirmed exfiltration of those documents was found in the report. Keep that caveat. It matters.

BleepingComputer also noted that Thailand's Ministry of Finance had not confirmed the breach when it covered the findings on July 24. Some artifacts showed targeting and access attempts rather than proved compromise of every referenced system. But Hunt.io said session files, deployed web shells, and internal-access evidence indicated multiple systems inside the ministry network were compromised. That is the part security teams should care about. The agent did not need to invent an attack from scratch. It just had to keep going once the operator gave it tools and direction.

The exposed directories also contained code aimed at Hadoop infrastructure, Apache Ambari, GlassFish, mail servers, and internal administrative panels. Some scripts included hardcoded credentials. Others tested access or attempted to deploy web shells. This was not a chatbot writing a phishing email. It was automation stitched into a live intrusion workflow.

Hades Makes This More Than An AI Story #

The same July 10 directory held 62 compiled payloads across Windows and Linux. Hunt.io said two analyzed samples belonged to the same previously unreported Go implant, which the operator called Hades. The malware communicated over HTTPS, used URI paths meant to look like normal web traffic, and supported remote command execution and file transfer. The Windows version added persistence through Registry Run keys and scheduled tasks, while the Linux version used cron jobs.

That pairing is the point. Hermes handled the tireless reconnaissance and command execution. Hades gave the operator a more durable implant. One is an agent. The other is malware. Together they show how quickly offensive workflows are being assembled from open tools, commodity scripts, and custom payloads.

Hunt.io traced the main exposed server to 43.246.208[.]207 on Hong Kong infrastructure and used TLS certificate pivots to identify two related hosts, one in Malaysia and one in Hong Kong. The researchers said ThaiCERT and Thailand's National Cyber Security Agency were notified on July 15 and acknowledged receipt the same day. Publication followed a seven-day disclosure window.

Here's the thing: the most dangerous lesson is not that an AI agent suddenly became a master hacker. It did not. The exposed logs show an operator setting objectives and providing tools. The danger is more ordinary than that. Agentic systems are now good enough to carry out dull, repetitive, high-volume intrusion tasks while a human steps back.

That changes the economics of attack. A person who once had to babysit enumeration can now assign it. A weakly supervised agent can scan and report back - summarising hosts, testing paths, flagging what's open. If you're defending enterprise systems, the question is not whether the model is brilliant. The question is whether your exposed services, stale credentials, and internal admin panels can survive an attacker who no longer gets tired.

Also read: AMD's MI355X Undercuts Nvidia's B300 on Cost to Run China's Kimi K3Anthropic Admits Its Own Bugs Broke Claude Code After Weeks of DenialAmazon Shuts Its AGI Lab and Cuts Jobs to Chase Enterprise AI Instead

── more in #ai-agents 4 stories · sorted by recency
── more on @hunt.io 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/a-hacker-turned-deep…] indexed:0 read:4min 2026-08-02 ·