Timeline

Open-source Hermes AI agent used in autonomous 'YOLO mode' attack on Thai Finance Ministry

Researchers found exposed attack logs showing an open-source Hermes AI agent operating with human-approval prompts disabled to autonomously perform privilege escalation and reconnaissance against Thai government infrastructure.

  • Security & misuse
  • Notable

Threat-intelligence firm Hunt.io and researcher Bob Diachenko reported finding an exposed, Hong Kong-hosted server containing roughly 470 megabytes of attack logs and tooling, revealing that operators had used Hermes — an open-source AI agent released earlier in 2026 — to automate an intrusion against Thailand’s Ministry of Finance. The logs showed Hermes running in “YOLO mode,” a setting that strips out the prompts that would otherwise require a human to approve dangerous commands, letting the agent carry out reconnaissance and privilege-escalation steps against ministry systems without step-by-step human sign-off.

Recovered artefacts showed the agent performing privilege-escalation enumeration, kernel-vulnerability scanning, service enumeration, and searches for exploitable SUID and SGID binaries, including a customised deployment of the LinPEAS privilege-escalation script, and targeting Hadoop clusters, Apache Ambari consoles, GlassFish administration panels and ministry mail servers using hardcoded credentials. The logs indicated a human-directed but largely unsupervised operation: operators supplied objectives while the agent executed the routine commands autonomously. Hunt.io linked the exposed server to further infrastructure in Malaysia and Hong Kong through shared TLS certificates.

Researchers notified ThaiCERT and Thailand’s National Cyber Security Agency on 15 July 2026; the Ministry of Finance had not confirmed a breach at the time of reporting. The incident was one of several mid-2026 cases in which an openly available agent framework, rather than a frontier lab’s own model, was the tool doing the autonomous work of an intrusion.

Referenced by