Hunt.io Finds Hermes AI Agent Running Unattended in Thai Ministry Intrusion Hunt.io says logs recovered from an exposed attacker server show the open-source Hermes AI agent running unattended during post-exploitation activity inside Thailand's Ministry of Finance. The firm observed 585 files and 470 MB of tooling between July 9 and 13; it says the agent enumerated hosts and files, while initial access and any data exfiltration remain unconfirmed. Hunt.io Finds Hermes AI Agent Running Unattended in Thai Ministry Intrusion Hunt.io says logs recovered from an exposed attacker server show the open-source Hermes AI agent running unattended during post-exploitation activity inside Thailand's Ministry of Finance. The firm observed 585 files and 470 MB of tooling between July 9 and 13; it says the agent enumerated hosts and files, while initial access and any data exfiltration remain unconfirmed. Hunt.io and security researcher Bob Diachenko say they recovered attacker infrastructure that exposed a rare view of an AI agent operating during a live intrusion. Their July 23 report attributes the activity to a server used against Thailand's Ministry of Finance and says the open-source Hermes agent was run in an unattended setting known as "YOLO" mode. What the recovered material showed Hunt.io says its monitoring captured three open directories on a Hong Kong-hosted server between July 9 and 13. The directories contained 585 files totaling 470 MB, including exploit code, web shells, hardcoded credentials, post-exploitation scripts and logs produced by Hermes. Thailand's national CERT and National Cyber Security Agency were notified on July 15 and acknowledged the report, according to Hunt.io. The recovered Hermes logs show the agent running host and kernel checks, reading LinPEAS output, listing files and recursively inspecting a ministry web root. That is evidence of automated post-exploitation work, not evidence that the agent found the original entry point. Hunt.io says initial access was unclear. The Hacker News also reports that the public material does not show data leaving the network. The server included 62 builds of a Windows-and-Linux implant the operator called Hades, along with scripts aimed at internal Hadoop services. Those artifacts show what the operator prepared, but they do not establish that every tool was successfully deployed inside the ministry. Hunt.io assesses only low-to-medium confidence that the operator was Chinese-speaking and does not name a threat group. Why the incident matters Hermes is a general-purpose open-source assistant, not malware, and the reporting does not describe a vulnerability in the agent. The operator disabled approval prompts and used the software to repeat familiar security tasks after a human had already selected and accessed the target. For defenders, the useful signal is operational: agentic tooling can compress the time between reconnaissance steps without introducing a distinctive new command line. Controls still need to focus on exposed web shells, unusual web-server access to internal systems, privileged file discovery, vulnerable kernels, weak Hadoop authentication and predictable agent output directories. The event demonstrates autonomous execution in an intrusion, while leaving attribution, initial access and exfiltration unresolved. Key Points - 1Hunt.io says it observed three exposed attacker directories containing 585 files and 470 MB of tooling between July 9 and 13. - 2Recovered logs show Hermes running unattended post-exploitation tasks, but do not show how the operator gained initial access. - 3The public evidence does not confirm data exfiltration or deployment of every staged exploit and implant. - 4The incident concerns operator misuse of a general-purpose agent, not a reported flaw in Hermes. Scoring Rationale The report documents unattended agent execution during a national-government intrusion and provides unusually detailed artifacts and defensive indicators. Impact is tempered because the ministry-specific findings originate with one research team, the initial-access path is unknown, and public evidence does not confirm exfiltration or a named threat actor. Sources Primary source and supporting public references used for this report. Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems