Hermes logs show AI-assisted reconnaissance in alleged Thai finance ministry intrusion
Exposed attacker infrastructure contained logs showing the Hermes AI agent running unattended reconnaissance and privilege-escalation checks against systems associated with Thailand's Ministry of Finance. The artifacts show deliberate, operator-directed targeting, but they do not establish the initial access path, the full extent of compromise or data theft.
- Logs from exposed attacker infrastructure show Hermes performing unattended reconnaissance against systems associated with Thailand's Ministry of Finance.
- The evidence makes targeting and operator-directed automation credible; it does not confirm how attackers entered the ministry, how far they got or whether data left its network.
- The case is less evidence of an autonomous attack than of an operator using an AI agent alongside conventional intrusion tooling.
An exposed staging server recorded an operator using Hermes—an open-source, persistent AI agent released in February 2026—to run reconnaissance and privilege-escalation checks without approval prompts against systems associated with Thailand's Ministry of Finance. The underlying research is unusually detailed, but it documents a campaign in progress rather than a confirmed account of its impact.
Thailand's Ministry of Finance oversees public finance, taxation, the national treasury, government property, state-owned enterprises and financial institutions. Its Office of the Permanent Secretary sets the ministry's strategic plan and oversees regular operations across subordinate agencies. That makes the reported targets consequential, but it also raises the evidentiary bar: a file naming an internal system or an attempt against it is not by itself proof of a successful intrusion.

Hunt.io company-reported file counts for the 9, 10 and 13 July directories. Source: Hunt.io.
What the exposed files establish
Hunt.io, a threat-intelligence company that conducted the investigation with security researcher Bob Diachenko, says it archived three open directories on a Hong Kong-hosted server between July 9 and July 13. The directories held 585 files totaling 470 MB, including web shells, exploit code, credentials, custom scripts, compiled payloads and Hermes output.
The material named ministry hosts and internal IP addresses and included tools aimed at a Hadoop cluster and its Ambari management platform, a GlassFish administration console, an administrative panel and ministry mail systems. One script attempted a HiveServer2 path using hardcoded credentials and a malicious Java user-defined function; others attempted mailbox authentication. That is target-specific preparation, not generic AI-assisted experimentation.
It is not, however, a complete breach narrative. The says the ministry had not confirmed a compromise. Hunt.io's own review also distinguishes between evidence of contact and authenticated access: cookie files from an administrative panel show that the operator reached the panel, but not that the operator logged in. It could not verify whether a GlassFish web shell had been deployed, and it could not determine the initial-access method.