Hackers used an autonomous AI agent in a Thailand finance ministry hack, according to Hunt.io, which said it found attacker-controlled infrastructure exposing malware, credentials, scripts and logs while the operation was still active.
The cybersecurity firm said in a report released last week that the exposed server contained hundreds of publicly reachable files tied to the intrusion. Hunt.io said the material showed the attackers had already reached multiple systems inside Thailand’s Ministry of Finance, though the firm has not determined how the first compromise happened.
The tool doing much of the work, according to Hunt.io, was Hermes, an open-source AI agent released earlier this year by AI research company Nous Research. The operators enabled its so-called YOLO mode, which let the software run commands without stopping for human approval. That is the part defenders should read twice, preferably before procurement teams discover a new fondness for agentic automation.
How did hackers use an AI agent against Thailand’s finance ministry?
Hunt.io said Hermes autonomously probed the ministry’s network, reviewed internal files, collected system details and searched for ways to raise privileges. In plain terms, the agent acted like a tireless junior intruder: it looked around, ran commands, wrote down what it found and kept asking the environment what else it could touch.
The exposed infrastructure also held exploits for known software flaws, ministry-specific scripts, stolen usernames and passwords, live authentication cookies and a malware family Hunt.io calls Hades. The firm described Hades as a previously undocumented custom backdoor meant to preserve access after the initial breach.
Hunt.io said it found Windows and Linux variants of Hades. Both versions were capable of receiving remote commands and moving files, according to the researchers. Those features are ordinary backdoor plumbing, which is the point: once installed, the malware gives an operator a reusable doorway into compromised systems.
The researchers identified the Ministry of Finance as the likely target because many scripts named internal systems belonging to the agency, including administrative web portals, email services and document management platforms. Other tools were built to test ministry email passwords and interact with particular internal services, Hunt.io said.
Despite evidence of access to several ministry systems, Hunt.io said it did not find signs that data had been taken out of the network. The activity it observed centered on reconnaissance, credential theft and network mapping, all useful groundwork for later operations.
Who was behind the operation?
Hunt.io did not link the campaign to a named hacking group. The firm said several indicators pointed to Chinese-speaking operators, but it did not publicly attribute the activity beyond that assessment.
According to Hunt.io, ThaiCERT and Thailand’s National Cyber Security Agency were notified on July 15. The firm said it traced the malicious activity back to at least mid-to-late June.
The Ministry of Finance has not publicly acknowledged the incident and did not respond to a request for comment, according to the reporting on the case. Thai cybersecurity officials said Monday that they would strengthen national defenses against cyberattacks involving AI agents, though they did not directly cite Hunt.io’s findings.
“Thailand must be able to fully benefit from AI while systematically managing the associated risks to prepare for future cyber threats,” Theerawut Wittayakorn, deputy secretary-general of Thailand’s National Cyber Security Committee, said after a meeting.
The case lands in the same month that AI development platform Hugging Face disclosed a breach by an autonomous AI agent later confirmed to belong to OpenAI. Hugging Face said that agent used two previously unknown software vulnerabilities and stolen credentials to access its systems.
This story draws on original reporting from The Record.