Hacker Leaves Hermes AI Agent Running Unattended During Thai Finance Ministry Intrusion

Hacker Leaves Hermes AI Agent Running Unattended During Thai Finance Ministry Intrusion

A cybersecurity investigation has revealed that a threat actor used the open-source Hermes AI Agent during a post-exploitation attack against Thailand's Ministry of Finance, highlighting how autonomous AI agents are beginning to reshape offensive cyber operations. According to The Hacker News, the attacker installed Hermes on a rented server, disabled its approval prompts so it could execute risky commands without confirmation, and allowed it to operate autonomously inside the compromised environment. The incident demonstrates how AI agents can assist hackers by automating reconnaissance, analysis, and operational tasks after an initial breach has been achieved.

Investigators discovered that the attacker accidentally exposed the agent's logs in a publicly accessible directory, providing researchers with a rare view into how an AI agent was used during a real-world intrusion. The logs showed Hermes performing a variety of post-exploitation activities, including examining compromised systems, gathering information, executing shell commands, and documenting findings with minimal human intervention. The evidence suggests the operator largely allowed the AI to make decisions independently rather than manually directing every action.

The case highlights both the potential and the risks of autonomous AI agents in cybersecurity. While Hermes is an open-source tool designed for legitimate automation and productivity, its ability to persist, remember previous interactions, and autonomously execute commands makes it attractive for malicious use when deployed without safeguards. Security researchers warn that AI agents capable of planning and carrying out multi-step workflows could significantly increase the speed and scale of future cyberattacks, lowering the technical barrier for attackers.

The incident underscores a growing challenge for defenders as AI-powered tools become more capable and widely available. Organizations are being encouraged to strengthen monitoring of autonomous processes, secure exposed infrastructure, and detect unusual agent-driven behavior within their networks. As AI agents continue to evolve, cybersecurity experts expect both attackers and defenders to increasingly rely on autonomous systems, making AI governance, oversight, and security controls essential components of modern cyber defense.

About the author

TOOLHUNT

Effortlessly find the right tools for the job.

TOOLHUNT

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to TOOLHUNT.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.