Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

    Date: 07/27/2026

    Severity: Medium

    Summary

    A suspected cyberespionage campaign targeted Thailand's Ministry of Finance (MOF) using the autonomous Hermes AI agent running in unattended (YOLO) mode to automate network reconnaissance and post-compromise activities. The attackers deployed the previously unreported Hades Go-based implant, webshells, HTTP tunnels, and staged exploits for CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), and CVE-2017-7269 (IIS WebDAV) to enable persistent access and expand compromise. The operation also leveraged stolen credentials to target Apache Hadoop infrastructure and was traced to exposed attack infrastructure hosted in Hong Kong. 

    Indicators of Compromise (IOC) List

    IP Address

    43.246.208.207

    103.97.0.57

    118.107.222.232

    202.181.27.115

    Hash

    0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc

    a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509

    ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2

    b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53

    d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2

    c74010aa82e8164c8d4ca9e073ec6b9a762e53db67498b22f5ccaef3a82853f

    576C70E12BE8B2E8E7C35A5FEB082E90621989ADCE8E64400126918D37F13E49

    5633BC0033FDE3AAD929D6CBD47C554E264180360B017AAE04687C2D6D83F753

    DBBB8A11A239DA11CBAF99F847A2D032F34D3B522E13B0FD4EF7B2649DA7123B

    9FF4B6D3B7DBB023BAD65D2538ADE745D46B763E5A12116C9C83AA2F6F5D96AA

    2A4CB412EFA93FED7C3B3B3E49D6247B11A95CE9FDDF71D9FE9DB8E5F0068E0D

    58338A93FEE4E008EA28E459C4D1598313D1524763AB13894AB63BF2BEC4302A

    FF662B60F6A142F99292FBDD65DD1CCD79DC9628686DDF5935C92F7FB1B62A81

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection 

    Detection Query 1 :

    dstipaddress IN ("103.97.0.57","43.246.208.207","202.181.27.115","118.107.222.232") or srcipaddress IN ("103.97.0.57","43.246.208.207","202.181.27.115","118.107.222.232")

    Detection Query 2 :

    sha256hash IN ("d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2","0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc","a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509","ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2","b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53","c74010aa82e8164c8d4ca9e073ec6b9a762e53db67498b22f5ccaef3a82853f","576C70E12BE8B2E8E7C35A5FEB082E90621989ADCE8E64400126918D37F13E49","5633BC0033FDE3AAD929D6CBD47C554E264180360B017AAE04687C2D6D83F753","DBBB8A11A239DA11CBAF99F847A2D032F34D3B522E13B0FD4EF7B2649DA7123B","9FF4B6D3B7DBB023BAD65D2538ADE745D46B763E5A12116C9C83AA2F6F5D96AA","2A4CB412EFA93FED7C3B3B3E49D6247B11A95CE9FDDF71D9FE9DB8E5F0068E0D","58338A93FEE4E008EA28E459C4D1598313D1524763AB13894AB63BF2BEC4302A","FF662B60F6A142F99292FBDD65DD1CCD79DC9628686DDF5935C92F7FB1B62A81")

    Reference:    

    https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent#Key_Findings                          


    Tags

    Threat ActorVulnerabilityCyber EspionageThailandFinancial ServicesAIExploitCVE-2021CVE-2017Credential HarvestingHong KongWebShell

    « Previous Article

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags