2026-10-11 17:12 UTC

Independent investigation will determine whether the Hermes AI agent materially automated an intrusion against Thailand's Finance Ministry and how much human direction the attack required.

state: expiredheat: lowuncertainty: highnovelscott: lowcyber-agents agentic-security autonomous-cyberattacksHermesThailand Finance Ministry

What is this?

Hunt.io and researcher Bob Diachenko reported an intrusion targeting Thailand’s Ministry of Finance in which the open-source Hermes AI agent allegedly ran unattended, conducting reconnaissance and data harvesting across compromised internal systems. The supplied snippets say Hermes executed post-exploitation tasks such as running LinPEAS, checking privileged binaries, and enumerating web roots with sensitive personnel data, while a separate Hades implant was staged on the same infrastructure. The evidence supports material automation, but does not independently establish how access was obtained, who operated the tools, or precisely how much human direction Hermes received beyond being configured to run unattended.

Why it matters to Scott

No intersection was found in Scott’s wikis or the radar’s accumulated pages. The incident is broadly adjacent to agentic security, but the supplied material does not connect it to a position, project, or previously tracked development of Scott’s, and the unresolved degree of autonomy limits its significance.
queries asked of Scott's wikis
  • autonomous cyber agents and human-in-the-loop boundaries
  • coding-agent harnesses for unattended tool execution
  • agent permissions sandboxing and blast-radius controls
  • AI agent audit trails and action provenance
  • dual-use open-source agents and capability governance
  • security implications of YOLO-mode agent autonomy

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (4) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHermes AI agent used to automate attack on Thai Finance Ministrysbulaev10
🟧 echo.blog ⭐Original joint Hunt.io/Bob Diachenko research. It reports that exposed directories revealed Hermes running in unattended “YOLO” mode againstHunt.io and Bob Diachenko——
🟧 hnHermes AI agent used to automate attack on Thai Finance MinistryBrajeshwar30
🟧 hnInvestigating three real-world incidents in our cybersecurity evaluationssurprisetalk217172

Interpretation history

Decision trace