Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find

· Original article ↗

Summary

Hunt.io researchers found an unattended Hermes agent, Hades implant, web shells and tailored attack tools targeting Thailand’s Ministry of Finance. Evidence indicates access to multiple systems; the initial access method and any data exfiltration remain unconfirmed.

Key points

  • Researchers recovered three exposed directories on a Hong Kong-hosted server, containing 585 files and 470 MB of attack tools and credentials.
  • Hermes logs show the agent ran in unattended “YOLO” mode, enumerated ministry hosts and files, and ran privilege-escalation checks.
  • Recovered session material, a deployed web shell and internal network access indicate compromise of multiple ministry systems; the initial access method is unknown.
  • A custom cross-platform Go implant, Hades, supports command execution, persistence, file transfer and HTTPS command-and-control.
  • Targeting tools included scripts for Hadoop HiveServer2 and Ambari, GlassFish, ministry mail systems and privilege-escalation exploits.
  • Researchers found no evidence that files were exfiltrated; they recommend reviewing HiveServer2 authentication and UDF controls, auditing web roots and patching affected systems.

Article Details

Attack Vectors
  • Initial access to Thailand's Ministry of Finance network was not established from the recovered files.
  • A staged HiveServer2 script attempts SASL PLAIN authentication with default credentials, registers a malicious Java UDF to execute shell commands, and retrieves output through WebHDFS.
  • GlassFish scripts attempt to authenticate to an internal admin console with default credentials and deploy JSP web shells packaged as WAR files. Successful deployment of those WAR files was not confirmed.
  • A PHP web shell disguised as a Linux journal cache file was deployed on a ministry web server.
  • Perl and Python scripts test ministry mailbox credentials; other staged code targets sudo, polkit pkexec, and IIS 6.0 WebDAV vulnerabilities.
  • Recovered Hermes logs show unattended agent activity involving host and file enumeration and privilege-escalation assessment. No exfiltration of the enumerated files was evidenced.
  • Analyzed Hades builds communicate with hardcoded controllers over HTTPS. The builds include persistence, proxy, file-transfer, and platform-specific execution capabilities.
Defensive Notes
  • Review HiveServer2 authentication mode and enforce its UDF blocklist.
  • Recursively audit web roots for PHP files with leading-dot names that imitate system files.
  • Patch sudo to 1.9.5p2 or later and check polkit versions for CVE-2021-4034.
  • Disable WebDAV on remaining IIS 6.0 instances or migrate off the platform.
  • Alert when web server processes connect to internal service ports such as 10000 or 50070.
  • Change default GlassFish admin-console credentials and restrict console access to trusted networks.

Indicators of compromise

TypeIndicatorContext
DOMAINredhatupdating432[.]dnsrd[.]comDomain resolving to the staging server; the article notes its presence predates the observed ministry activity.
IPV4103[.]97[.]0[.]57SSH client address in the recovered Hermes configuration, identified as an operator access host for the staging server.
IPV4118[.]107[.]222[.]232Additional server linked to the operator infrastructure through the shared TLS certificate fingerprint.
IPV4202[.]181[.]27[.]115Server linked through TLS certificates and hardcoded as a controller in an analyzed Hades Linux binary.
IPV443[.]246[.]208[.]207Operator staging server with exposed attack directories; also hosted a VShell C2 server and was a hardcoded Hades controller.
SHA2560f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fcVShell Linux stage-one payload recovered from the server.
SHA2562a4cb412efa93fed7c3b3b3e49d6247b11a95ce9fddf71d9fe9db8e5f0068e0dTLS certificate fingerprint listed for a server linked to the operator infrastructure.
SHA2565633bc0033fde3aad929d6cbd47c554e264180360b017aae04687c2d6d83f753TLS certificate fingerprint listed for the operator staging server.
SHA256576c70e12be8b2e8e7c35a5feb082e90621989adce8e64400126918d37f13e49TLS certificate fingerprint listed for the operator staging server.
SHA25658338a93fee4e008ea28e459c4d1598313d1524763ab13894ab63bf2bec4302aTLS certificate fingerprint listed for a server also identified as a Hades controller.
SHA2569ff4b6d3b7dbb023bad65d2538ade745d46b763e5a12116c9c83aa2f6f5d96aaTLS certificate fingerprint listed for the operator staging server.
SHA256a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509VShell Windows stage-one payload recovered from the server.
SHA256b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53VShell Windows stage-two payload recovered from the server.
SHA256d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2Analyzed Hades Linux binary, multipathd_04d0.
SHA256dbbb8a11a239da11cbaf99f847a2d032f34d3b522e13b0fd4ef7b2649da7123bTLS certificate fingerprint listed for the operator staging server.
SHA256ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2VShell Linux stage-two payload recovered from the server.
SHA256ff662b60f6a142f99292fbdd65dd1ccd79dc9628686ddf5935c92f7fb1b62a81TLS certificate fingerprint listed for a server also identified as a Hades controller.

MITRE ATT&CK

T1036.005 · Match Legitimate Resource Name or LocationHades binaries used names resembling legitimate processes and daemons, while a PHP web shell imitated a Linux journal cache file.T1053 · Scheduled Task/JobAnalyzed Hades builds include scheduled-task persistence on Windows and cron persistence on Linux.T1055.012 · Process HollowingThe Hades Windows build includes reflective PE loading through process hollowing into svchost.exe.T1059 · Command and Scripting InterpreterThe malicious Hive UDF was written to execute shell commands passed through Hive SQL queries.T1068 · Exploitation for Privilege EscalationExploit code for the sudo and polkit pkexec local privilege-escalation vulnerabilities was staged.T1071.001 · Web ProtocolsHades communicates over HTTPS using paths that resemble static web assets for check-in, tasking, and uploads.T1072 · Software Deployment ToolsAn Apache Ambari command-execution payload named an internal HDFS DataNode; execution of the payload was not confirmed.T1082 · System Information DiscoveryRecovered Hermes logs captured LinPEAS output, including kernel vulnerability checks and service enumeration on a ministry host.T1083 · File and Directory DiscoveryHermes logs show recursive web-root enumeration and searches for SUID/SGID binaries.T1090.001 · Internal ProxyThe staged material included suo5 HTTP tunnels, and GlassFish scripts used a local SOCKS5 proxy; the proxy tunnel's status was not confirmed.T1110.003 · Password SprayingPerl and Python scripts tested ministry mailbox credentials using hardcoded addresses and passwords and a targeted wordlist.T1113 · Screen CaptureThe Hades Windows build includes GDI-based screenshot capture.T1190 · Exploit Public-Facing ApplicationAn IIS 6.0 WebDAV exploit module and target-specific shellcode were staged; their successful use was not established.T1505.003 · Web ShellA PHP web shell was deployed on a ministry web server; JSP web shells were also packaged in WAR files for attempted GlassFish deployment.T1539 · Steal Web Session CookieRecovered files contained ministry admin-panel session and CSRF tokens and Alfresco session material; the admin-panel tokens alone do not establish authenticated access.T1547.001 · Registry Run Keys / Startup FolderThe analyzed Hades Windows build includes Registry Run key persistence.

CVE

People

Malware

Products

AlfrescoA text file, alf_cookie.txt contains Alfresco session material for an internal ministry address, adding a document management platform to the operator's list of targets.Apache AmbariIn addition to the Hive scripts, an Apache Ambari command-execution payload, ambari_cmd.json names an internal HDFS DataNode specifically by its hostname. The Ambari payloads target the management layer rather than theApache Hadoopsuo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and Apache Hadoop.Apache HiveServer2The 13 July directory contains over a dozen files related to Apache HiveServer2 exploitation, including multiple Python scripts, compiled Java code. A compressed archive named hive_full_v3.tar.gz, bundled the Thrift andGlassFishGlassFish Console AccessIIS 6.0a Metasploit module (cve2017_7269.rb) targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and path files pointingpolkitthe heap overflow. The exploit affects CentOS 6 and 7 running sudo 1.8.x. CVE-2021-4034 (PwnKit), the polkit pkexec local privilege-escalation vulnerability was also observed on the server.sudoThe operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).Windows Server 2003targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and path files pointing to the ministry's intranet

Tools

FOFApassword contains the Chinese word "Leishen," which roughly translates to "Thunder God." An API key for FOFA, a Chinese internet asset reconnaissance platform was also observed.HermesThe attack, targeting Thailand's Ministry of Finance (MOF) was largely driven by Hermes, an autonomous AI agent using "YOLO" mode. Additionally, we identified an unreported Go implant the operator refers to as "Hades".Hunt.io Attack CaptureHunt.io Attack Capture archived three open directories on 43.246.208[.]207 during the period of 9 - 13 July 2026, totaling 585 files and 470 MB of attack code and stolen credentials.HuntSQLof the certificate itself rather than its contents. Querying that hash alongside the www common name in HuntSQL returned two additional, related hosts: 118.107.222[.]232 (The Gigabit, Malaysia) and 202.181.27[.]115LinPEASThe Hermes logs found within the three directories capture the agent enumerating ministry hosts, traversing files, and capturing LinPEAS output from an adjacent host.MetasploitFor Windows, a Metasploit module (cve2017_7269.rb) targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and pathsuo5on AS132883 (TOPIDC) in Hong Kong. The directories contained exploit code for multiple CVEs, webshells, suo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and ApacheVShellidentified as high risk due to the historical presence of a ShadowPad controller, and currently hosting a VShell C2 server on port 21083. A single domain, redhatupdating432.dnsrd[.]com resolves to the server, though

Countries

Industries

Related Articles