{"id":6950,"date":"2026-07-24T10:52:22","date_gmt":"2026-07-24T10:52:22","guid":{"rendered":"https:\/\/lockitsoft.com\/?p=6950"},"modified":"2026-07-24T10:52:22","modified_gmt":"2026-07-24T10:52:22","slug":"the-ministry-of-finance-of-thailand-targeted-by-ai-driven-espionage-campaign","status":"publish","type":"post","link":"https:\/\/lockitsoft.com\/?p=6950","title":{"rendered":"The Ministry of Finance of Thailand Targeted by AI-Driven Espionage Campaign"},"content":{"rendered":"<p>An sophisticated cyberattack campaign has successfully infiltrated the network of Thailand&#8217;s Ministry of Finance, exploiting a popular open-source AI assistant and leveraging misconfigurations to probe for sensitive data. The operation, uncovered by threat intelligence firm Hunt.io and researcher Bob Diachenko, highlights a concerning evolution in AI-assisted cyber warfare, where autonomous agents are increasingly being deployed to conduct reconnaissance and data exfiltration. The attackers utilized an AI tool named Hermes, designed for task management, by disabling its safety protocols and directing it to operate independently within the ministry&#8217;s internal systems. This incident, discovered on July 15, 2024, has raised alarm bells regarding the potential for AI to be weaponized for espionage on a national scale.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#The_Genesis_of_the_Attack_An_Autonomous_AI_Agent_on_the_Loose\" >The Genesis of the Attack: An Autonomous AI Agent on the Loose<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#A_Departure_from_Previous_AI-Assisted_Attacks\" >A Departure from Previous AI-Assisted Attacks<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#The_Human_Element_Strategic_Targeting_and_Reconnaissance\" >The Human Element: Strategic Targeting and Reconnaissance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#The_Autonomous_Agents_Actions_A_Step-by-Step_Breakdown\" >The Autonomous Agent&#8217;s Actions: A Step-by-Step Breakdown<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#The_Vulnerable_Gateway_Hadoop_and_Unsecured_Services\" >The Vulnerable Gateway: Hadoop and Unsecured Services<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#The_Unseen_Trail_How_the_Attack_Was_Uncovered\" >The Unseen Trail: How the Attack Was Uncovered<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/lockitsoft.com\/?p=6950\/#Broader_Impact_and_Implications\" >Broader Impact and Implications<\/a><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"The_Genesis_of_the_Attack_An_Autonomous_AI_Agent_on_the_Loose\"><\/span>The Genesis of the Attack: An Autonomous AI Agent on the Loose<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The core of this breach lies in the unauthorized deployment of the Hermes AI agent. This open-source assistant, developed by Nous Research, is typically used for benign purposes such as managing emails, automating routine tasks, and interacting via messaging platforms like Telegram and Slack. However, in this instance, the attacker configured Hermes with a specific operational mode known as &quot;YOLO&quot; (You Only Look Once). This mode, a documented feature of the agent, bypasses the need for explicit human authorization before executing commands, even those deemed risky.<\/p>\n<p>The attacker essentially rented server space, installed Hermes, disabled the safety feature, and then pointed the agent towards the Ministry of Finance&#8217;s network. Once inside, the AI agent autonomously began its mission: identifying potential vulnerabilities, searching for ways to elevate its privileges to root access, meticulously examining file systems, and systematically crawling through a vast repository of staff personnel records that spanned back to 2012. This autonomous operation allowed the agent to perform a continuous and deep reconnaissance without direct human intervention for each step.<\/p>\n<p>The discovery of the attack was serendipitous. The operator, seemingly unaware of the exposure, left the agent&#8217;s operational logs accessible on a publicly listed web server. This oversight allowed Hunt.io and Bob Diachenko to stumble upon the data, which included not only the agent&#8217;s activity logs but also 585 files and approximately 470 MB of tooling used in the attack. This trove of information provided a detailed, albeit disturbing, look into the methodology employed.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"A_Departure_from_Previous_AI-Assisted_Attacks\"><\/span>A Departure from Previous AI-Assisted Attacks<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This incident marks a significant departure from previously reported AI-assisted cyberattacks. In November 2023, Anthropic disclosed an incident where a Chinese threat actor attempted to use its Claude Code AI for espionage. However, in that case, the attackers had to actively &quot;trick&quot; the model into cooperating, and their accounts were eventually banned once the malicious activity was detected. The key difference here is that Hermes was deployed on infrastructure controlled entirely by the attacker. There was no central vendor like Anthropic monitoring usage or enforcing terms of service. The attacker&#8217;s own machine was running the AI, and the &quot;YOLO&quot; mode meant there was no intermediary to flag or block potentially harmful actions. This self-contained nature of the operation makes it particularly difficult to detect and prevent.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_Human_Element_Strategic_Targeting_and_Reconnaissance\"><\/span>The Human Element: Strategic Targeting and Reconnaissance<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>While the AI agent performed the repetitive and systematic tasks of reconnaissance, the human operator was crucial in providing the strategic direction and initial access. Hunt.io recovered a hidden web shell, a piece of malicious code designed to provide remote access, planted on a ministry web server. This indicates that the operator was already inside the network before deploying the Hermes agent. Additionally, the investigation uncovered scripts specifically written to interact with internal Hadoop systems and a mail-testing script containing hardcoded stolen mailbox passwords.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg8qmYxOjHl19UJl8lK9TMJt86it1bULCh3SK1wSiD4JjiKU98fsHnko_QWzUWuG2ZmoHG7yxLrIgSTFRCKep1Ebj0JAH8xuTLFP_aIzGpTobs7C8u5OKGGTq79vqkHpY_Iy6LIEG-AHv-_uSJTVt2kxapGAu7qjfgiT4qpIAtnlfK3bR8he5-dubMNLYs\/s1700-e365\/hermes-agent.jpg\" alt=\"Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>The recovered data does not yet show any evidence of data exfiltration from the ministry&#8217;s network, and the exact method by which the operator initially gained access remains unknown. Thailand&#8217;s national Computer Emergency Response Team (CERT) and cybersecurity agency were notified of the breach on July 15, 2024. As of July 24, 2024, neither agency had released any public statements regarding the incident.<\/p>\n<p>The operational scripts revealed a crucial detail: they were designed to exploit a known vulnerability in Hadoop database services that, by default, accept any password. This allowed the operator to gain unauthorized access to the vast data stores managed by the ministry. The human element was also evident in the sophisticated targeting. Hunt.io&#8217;s analysis showed that the password list used by the operator was not a generic dictionary but was constructed using the ministry&#8217;s own departmental abbreviations. Furthermore, shellcode was found to contain hardcoded paths pointing into the ministry&#8217;s internal network, demonstrating a deep understanding of the target environment.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_Autonomous_Agents_Actions_A_Step-by-Step_Breakdown\"><\/span>The Autonomous Agent&#8217;s Actions: A Step-by-Step Breakdown<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The Hermes agent&#8217;s activities are meticulously documented in five files named <code>call_00_*.txt<\/code>. These logs provide a chronological account of the agent&#8217;s actions within the ministry&#8217;s network. The sequence of operations included:<\/p>\n<ul>\n<li><strong>Kernel Vulnerability Scanning:<\/strong> The agent initiated scans against a ministry host, searching for potential vulnerabilities in the Linux kernel.<\/li>\n<li><strong>Second LinPEAS Run:<\/strong> A subsequent execution of LinPEAS, a well-known script designed to identify privilege escalation pathways on Linux systems.<\/li>\n<li><strong>Elevated-Permission Binary Sweep:<\/strong> The agent searched for files with elevated permissions, a common tactic to identify potential weak points for privilege escalation.<\/li>\n<li><strong>Filesystem Listing:<\/strong> A comprehensive listing of files and directories within accessible parts of the file system.<\/li>\n<li><strong>Recursive Directory Crawl:<\/strong> The agent performed a deep, recursive crawl of the web root belonging to the Office of the Permanent Secretary.<\/li>\n<\/ul>\n<p>This crawl uncovered a significant volume of sensitive documents, including Office documents, performance evaluations, and, critically, personnel records dating back to 2012. While the logs confirm the agent&#8217;s access to and reading of these directories, they do not indicate that any of the files were actually exfiltrated.<\/p>\n<p><strong>Exploiting Kernel Vulnerabilities:<\/strong> The customized LinPEAS script handed to the agent was not a standard version. It specifically checked for four known Linux kernel vulnerabilities: Copy Fail (CVE-2026-31431), Dirty Frag (CVE-2026-43284 and CVE-2026-43500), and DirtyClone (CVE-2026-43503). These vulnerabilities, when successfully exploited under specific conditions, can grant a local user root privileges. However, the recovered materials do not specify the ministry&#8217;s kernel version, nor do they confirm whether any of these exploits were successfully executed. The operator&#8217;s scripts were prepared weeks in advance of the attack, suggesting a well-planned operation.<\/p>\n<p><strong>Attribution Indicators:<\/strong> Further analysis of the attack infrastructure provides potential clues about the perpetrators. The operator&#8217;s SSH session into the staging server originated from an IP address associated with Hong Kong (103.97.0[.]57). The web interface password for the Hermes agent contained the Chinese word &quot;Leishen,&quot; meaning &quot;thunder god.&quot; Additionally, an API key for FOFA, a Chinese asset-search service, was found alongside this password. The same staging server had previously hosted a ShadowPad controller and currently runs a VShell command-and-control listener. Based on these indicators, Hunt.io assesses with low-to-medium confidence that the operator is Chinese-speaking or fluent in the language. However, no specific threat group has been definitively linked to this attack.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_Vulnerable_Gateway_Hadoop_and_Unsecured_Services\"><\/span>The Vulnerable Gateway: Hadoop and Unsecured Services<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A significant portion of the custom code deployed by the attacker was directed at the ministry&#8217;s Hadoop cluster, a system designed for storing and querying massive datasets. A script named <code>hive_rce_py2.py<\/code> was observed connecting to HiveServer2, the SQL interface for the Hadoop cluster, on an internal machine at port 10000. The connection was established by sending a password.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" alt=\"Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<p>This exploit hinges on a critical security lapse: Apache&#8217;s own documentation for HiveServer2 indicates that the default authentication mode is &quot;NONE,&quot; meaning it accepts any provided password without verification. This configuration flaw effectively turned the SQL front-end into an open door for unauthorized access.<\/p>\n<p>Once connected, the script installed a malicious Java add-on, <code>HiveCmd.jar<\/code>, as a user-defined function (UDF). UDFs allow users to execute operating system commands through ordinary database queries and retrieve the results. Cloudera, a prominent Hadoop vendor, has warned that the ability to install such functions can enable attackers to run arbitrary code with the privileges of the Hive service account, granting them access to highly sensitive data.<\/p>\n<p><strong>Additional Exploitation Attempts:<\/strong> Beyond the Hadoop cluster, the attacker also deployed a previously undocumented Go implant named Hades. This implant was compiled for both Windows and Linux, with 62 copies found on the staging server. While Hunt.io analyzed one copy of each operating system, the remaining 60 were not individually examined. The hardcoded addresses within Hades suggest a connection to a second Hong Kong-based host, though no recovered artifact confirms Hades successfully communicating with a ministry machine.<\/p>\n<p>Furthermore, separate scripts were found that tested default credentials against an internal GlassFish console. Additionally, exploit code for three older vulnerabilities affecting <code>polkit<\/code>, <code>sudo<\/code>, and IIS 6.0 was present, indicating a broad reconnaissance effort across various potential attack vectors.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_Unseen_Trail_How_the_Attack_Was_Uncovered\"><\/span>The Unseen Trail: How the Attack Was Uncovered<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The method by which the attack was ultimately revealed is as critical as the attack itself. The Hermes agent, while designed for autonomy, still leaves a digital footprint. The agent&#8217;s web panel typically returns a &quot;HermesWebUI&quot; server header. A search for this header, as of Hunt.io&#8217;s July 23 report, revealed approximately 5,900 scan events over a month, indicating numerous instances of the agent being used.<\/p>\n<p>However, the more significant discovery point was the consistent presence of a <code>\/hermes-results\/<\/code> folder where the agent reliably stored its findings. This folder, with its predictable naming conventions for the files within, was indexed by Hunt.io&#8217;s tools. The search turned up 575 hits on July 23, each representing a host and filename pair. Crucially, it was not a sophisticated security control that exposed the operator, but rather a simple directory listing enabled on the web server. This highlights how basic misconfigurations can have catastrophic security implications.<\/p>\n<p>The implications of this attack are far-reaching. The seamless integration of AI into the cyberattack lifecycle blurs the lines between human-led operations and autonomous malicious activity. The &quot;YOLO&quot; mode employed by Hermes effectively removes the human element from the immediate execution loop, allowing for rapid and relentless probing of target systems. While the human operator still directs the overall campaign, the AI agent can operate tirelessly, identifying and exploiting vulnerabilities at machine speed.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgSCKBkSdUM0uA5ME91bZSWcVCh-kj_CiE9s9bLyDfi_gSE6u3ahktClaacbb326UFij8EHtspWjLQ28B8xdWMyFe7guAQy9OWZ7OV-qZ9Q33Dn5Rjp7GzHbXml27X4v7YNxOoKFUSK0j-D8W7E92jYWSFVNNWQLPvtRTkVVQxGJ_H6Ja-qWwPYFay857o\/s1700-e365\/cookies.png\" alt=\"Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"Broader_Impact_and_Implications\"><\/span>Broader Impact and Implications<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The Ministry of Finance incident serves as a stark warning about the evolving threat landscape in the age of artificial intelligence. The ability to deploy AI agents that can operate with minimal human oversight presents a significant challenge for cybersecurity professionals. Traditional security measures, often designed to detect human-like behavior or specific attack patterns, may struggle to keep pace with the adaptability and speed of AI-driven attacks.<\/p>\n<p><strong>The Democratization of Sophisticated Attacks:<\/strong> Open-source AI tools like Hermes, when misused, can lower the barrier to entry for sophisticated cyberattacks. Individuals or groups with limited technical expertise can leverage these tools to conduct complex operations that were previously the domain of highly skilled nation-state actors.<\/p>\n<p><strong>The Need for Enhanced AI Security:<\/strong> This incident underscores the urgent need for developers of AI tools to implement robust security features and responsible deployment guidelines. While Hermes itself is not a hacking tool, its features can be exploited. The &quot;YOLO&quot; mode, while useful for legitimate automation, becomes a dangerous weapon when unchecked.<\/p>\n<p><strong>Proactive Threat Hunting and Incident Response:<\/strong> The discovery by Hunt.io and Bob Diachenko highlights the importance of proactive threat hunting and robust incident response capabilities. The ability to quickly analyze attacker infrastructure and identify exposed data is critical in mitigating the impact of such breaches.<\/p>\n<p><strong>Government and Critical Infrastructure Vulnerabilities:<\/strong> The targeting of a national Ministry of Finance emphasizes the vulnerability of critical government infrastructure to advanced cyber threats. The compromise of such an entity could have profound implications for national security and economic stability.<\/p>\n<p><strong>Future Outlook:<\/strong> As AI technology continues to advance, it is inevitable that both offensive and defensive cybersecurity capabilities will evolve in tandem. This incident is likely just the beginning of a new era of AI-driven cyber warfare, demanding continuous innovation and vigilance from the global cybersecurity community. The key takeaway is that the combination of human strategic intent and autonomous AI execution creates a potent and formidable threat that requires a fundamental rethinking of our defense strategies.<\/p>\n<!-- RatingBintangAjaib -->","protected":false},"excerpt":{"rendered":"<p>An sophisticated cyberattack campaign has successfully infiltrated the network of Thailand&#8217;s Ministry of Finance, exploiting a popular open-source AI assistant and leveraging misconfigurations to probe for sensitive data. The operation, uncovered by threat intelligence firm Hunt.io and researcher Bob Diachenko, highlights a concerning evolution in AI-assisted cyber warfare, where autonomous agents are increasingly being deployed &hellip;<\/p>\n","protected":false},"author":27,"featured_media":6949,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[108],"tags":[734,109,258,3411,173,1579,111,110,3441,3440],"class_list":["post-6950","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-protection","tag-campaign","tag-cybersecurity","tag-driven","tag-espionage","tag-finance","tag-ministry","tag-privacy","tag-security","tag-targeted","tag-thailand"],"_links":{"self":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6950"}],"version-history":[{"count":0,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6950\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/media\/6949"}],"wp:attachment":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}