Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Essential information
- Published
- 23/07/2026 22:59
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- apache hadoop targeting autonomous attack operations cve-2017-7269 cve-2021-3156 cve-2021-4034 cve-2026-31431 cve-2026-43284 cve-2026-43500 cve-2026-43503 government espionage hades hades implant hermes ai agent hiveserver2 exploitation shadowpad suo5 thailand ministry finance vshell yolo mode
- Related entities
- 7 vulnerabilities (cve), 17 indicators, 5 observables, 16 techniques (mitre), 5 malware
Description
Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.