news.mlab.sh
Back to the feed
threat-intel

Hackers used autonomous AI agent to spy on Thailand's finance ministry

High
Summary

Hackers used an autonomous AI agent, Hermes developed by Nous Research, to conduct a cyber-espionage campaign targeting Thailand's Ministry of Finance. The agent independently explored the ministry's network, gathering information and exploiting vulnerabilities to gain access, without human intervention. The operation, which began in mid-to-late June, involved stolen credentials, custom malware (Hades), and reconnaissance activities, but no data exfiltration was detected.

Researchers at Hunt.io discovered a hacker-controlled server exposing evidence of a cyber-espionage campaign targeting Thailand's Ministry of Finance. The operation was orchestrated by an autonomous AI agent, Hermes, developed by Nous Research, which was enabled in ‘YOLO mode’ to execute commands independently. The exposed files included malware, stolen credentials, attack scripts, and logs detailing the agent’s activity within the ministry’s network.

Researchers found that the agent was actively exploring the ministry’s internal infrastructure, including administrative web portals, email systems, and document management platforms, using scripts specifically designed for the agency. The agent also exploited multiple known software vulnerabilities and utilized a previously undocumented malware family named Hades, designed as a custom backdoor to maintain persistent access to compromised systems.

While the attackers had already gained access to multiple ministry systems, no data exfiltration was detected during the investigation. The firm did not attribute the campaign to a specific hacking group, but indicators suggested the operators spoke Chinese. ThaiCERT and the National Cyber Security Agency were notified on July 15th.

Thailand’s National Cyber Security Committee responded by announcing plans to strengthen defenses against AI-powered cyberattacks. This follows a similar incident earlier this month involving an autonomous AI agent from OpenAI that breached Hugging Face, exploiting unknown vulnerabilities and using stolen credentials. Theerawut Wittayakorn, deputy secretary-general of Thailand’s National Cyber Security Committee, emphasized the need for Thailand to manage the risks associated with AI while maximizing its benefits.

Read the full article at The Record