Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find

Summary
Hunt.io researchers found an unattended Hermes agent, Hades implant, web shells and tailored attack tools targeting Thailand’s Ministry of Finance. Evidence indicates access to multiple systems; the initial access method and any data exfiltration remain unconfirmed.
Key points
- Researchers recovered three exposed directories on a Hong Kong-hosted server, containing 585 files and 470 MB of attack tools and credentials.
- Hermes logs show the agent ran in unattended “YOLO” mode, enumerated ministry hosts and files, and ran privilege-escalation checks.
- Recovered session material, a deployed web shell and internal network access indicate compromise of multiple ministry systems; the initial access method is unknown.
- A custom cross-platform Go implant, Hades, supports command execution, persistence, file transfer and HTTPS command-and-control.
- Targeting tools included scripts for Hadoop HiveServer2 and Ambari, GlassFish, ministry mail systems and privilege-escalation exploits.
- Researchers found no evidence that files were exfiltrated; they recommend reviewing HiveServer2 authentication and UDF controls, auditing web roots and patching affected systems.
Article Details
- Attack Vectors
- Initial access to Thailand's Ministry of Finance network was not established from the recovered files.
- A staged HiveServer2 script attempts SASL PLAIN authentication with default credentials, registers a malicious Java UDF to execute shell commands, and retrieves output through WebHDFS.
- GlassFish scripts attempt to authenticate to an internal admin console with default credentials and deploy JSP web shells packaged as WAR files. Successful deployment of those WAR files was not confirmed.
- A PHP web shell disguised as a Linux journal cache file was deployed on a ministry web server.
- Perl and Python scripts test ministry mailbox credentials; other staged code targets sudo, polkit pkexec, and IIS 6.0 WebDAV vulnerabilities.
- Recovered Hermes logs show unattended agent activity involving host and file enumeration and privilege-escalation assessment. No exfiltration of the enumerated files was evidenced.
- Analyzed Hades builds communicate with hardcoded controllers over HTTPS. The builds include persistence, proxy, file-transfer, and platform-specific execution capabilities.
- Defensive Notes
- Review HiveServer2 authentication mode and enforce its UDF blocklist.
- Recursively audit web roots for PHP files with leading-dot names that imitate system files.
- Patch sudo to 1.9.5p2 or later and check polkit versions for CVE-2021-4034.
- Disable WebDAV on remaining IIS 6.0 instances or migrate off the platform.
- Alert when web server processes connect to internal service ports such as 10000 or 50070.
- Change default GlassFish admin-console credentials and restrict console access to trusted networks.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | redhatupdating432[.]dnsrd[.]com | Domain resolving to the staging server; the article notes its presence predates the observed ministry activity. |
| IPV4 | 103[.]97[.]0[.]57 | SSH client address in the recovered Hermes configuration, identified as an operator access host for the staging server. |
| IPV4 | 118[.]107[.]222[.]232 | Additional server linked to the operator infrastructure through the shared TLS certificate fingerprint. |
| IPV4 | 202[.]181[.]27[.]115 | Server linked through TLS certificates and hardcoded as a controller in an analyzed Hades Linux binary. |
| IPV4 | 43[.]246[.]208[.]207 | Operator staging server with exposed attack directories; also hosted a VShell C2 server and was a hardcoded Hades controller. |
| SHA256 | 0f8c905aa25c86f85454acb7e77bf5c50220c2a82e5b69a33741e55c8a85f2fc | VShell Linux stage-one payload recovered from the server. |
| SHA256 | 2a4cb412efa93fed7c3b3b3e49d6247b11a95ce9fddf71d9fe9db8e5f0068e0d | TLS certificate fingerprint listed for a server linked to the operator infrastructure. |
| SHA256 | 5633bc0033fde3aad929d6cbd47c554e264180360b017aae04687c2d6d83f753 | TLS certificate fingerprint listed for the operator staging server. |
| SHA256 | 576c70e12be8b2e8e7c35a5feb082e90621989adce8e64400126918d37f13e49 | TLS certificate fingerprint listed for the operator staging server. |
| SHA256 | 58338a93fee4e008ea28e459c4d1598313d1524763ab13894ab63bf2bec4302a | TLS certificate fingerprint listed for a server also identified as a Hades controller. |
| SHA256 | 9ff4b6d3b7dbb023bad65d2538ade745d46b763e5a12116c9c83aa2f6f5d96aa | TLS certificate fingerprint listed for the operator staging server. |
| SHA256 | a9447ae174f4aa54f760b7d7cc985c1a970f31e151d3ff66fac247f99ba1b509 | VShell Windows stage-one payload recovered from the server. |
| SHA256 | b65b7ede835ebba36294d52d7780065523340ee09bb8b209ef2dc495e53dfd53 | VShell Windows stage-two payload recovered from the server. |
| SHA256 | d252ee7b348b7e43e432d8fb154465838f5cd5fb564905323460e6f0a0c7d1e2 | Analyzed Hades Linux binary, multipathd_04d0. |
| SHA256 | dbbb8a11a239da11cbaf99f847a2d032f34d3b522e13b0fd4ef7b2649da7123b | TLS certificate fingerprint listed for the operator staging server. |
| SHA256 | ec7e9ab43a0cc65d29f0b84a93ba88c43d01fed3dec5c968525dc73c03cbfda2 | VShell Linux stage-two payload recovered from the server. |
| SHA256 | ff662b60f6a142f99292fbdd65dd1ccd79dc9628686ddf5935c92f7fb1b62a81 | TLS certificate fingerprint listed for a server also identified as a Hades controller. |
MITRE ATT&CK
T1036.005 · Match Legitimate Resource Name or LocationHades binaries used names resembling legitimate processes and daemons, while a PHP web shell imitated a Linux journal cache file.T1053 · Scheduled Task/JobAnalyzed Hades builds include scheduled-task persistence on Windows and cron persistence on Linux.T1055.012 · Process HollowingThe Hades Windows build includes reflective PE loading through process hollowing into svchost.exe.T1059 · Command and Scripting InterpreterThe malicious Hive UDF was written to execute shell commands passed through Hive SQL queries.T1068 · Exploitation for Privilege EscalationExploit code for the sudo and polkit pkexec local privilege-escalation vulnerabilities was staged.T1071.001 · Web ProtocolsHades communicates over HTTPS using paths that resemble static web assets for check-in, tasking, and uploads.T1072 · Software Deployment ToolsAn Apache Ambari command-execution payload named an internal HDFS DataNode; execution of the payload was not confirmed.T1082 · System Information DiscoveryRecovered Hermes logs captured LinPEAS output, including kernel vulnerability checks and service enumeration on a ministry host.T1083 · File and Directory DiscoveryHermes logs show recursive web-root enumeration and searches for SUID/SGID binaries.T1090.001 · Internal ProxyThe staged material included suo5 HTTP tunnels, and GlassFish scripts used a local SOCKS5 proxy; the proxy tunnel's status was not confirmed.T1110.003 · Password SprayingPerl and Python scripts tested ministry mailbox credentials using hardcoded addresses and passwords and a targeted wordlist.T1113 · Screen CaptureThe Hades Windows build includes GDI-based screenshot capture.T1190 · Exploit Public-Facing ApplicationAn IIS 6.0 WebDAV exploit module and target-specific shellcode were staged; their successful use was not established.T1505.003 · Web ShellA PHP web shell was deployed on a ministry web server; JSP web shells were also packaged in WAR files for attempted GlassFish deployment.T1539 · Steal Web Session CookieRecovered files contained ministry admin-panel session and CSRF tokens and Alfresco session material; the admin-panel tokens alone do not establish authenticated access.T1547.001 · Registry Run Keys / Startup FolderThe analyzed Hades Windows build includes Registry Run key persistence.
CVE
CVE-2017-7269The operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).CVE-2021-3156The operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).CVE-2021-4034The operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).CVE-2026-31431CVE-2026-31431: Known as Copy Fail, this is another LPE vulnerability in the algif_aead module, which would allow an unprivileged user to overwrite privileged binaries in memory, escalating access to root.CVE-2026-43284CVE-2026-43284/CVE-2026-43500: (Dirty Frag), is a flaw in the Linux kernel allowing an unprivileged user to elevate access to root via a page-cache write vulnerability.CVE-2026-43500CVE-2026-43284/CVE-2026-43500: (Dirty Frag), is a flaw in the Linux kernel allowing an unprivileged user to elevate access to root via a page-cache write vulnerability.CVE-2026-43503CVE-2026-43503: Referred to as DirtyClone, this is a local privilege escalation (LPE) vulnerability in the Linux kernel.
People
Malware
Hadesagent using "YOLO" mode. Additionally, we identified an unreported Go implant the operator refers to as "Hades". Active session cookie files, deployed webshells, and internal network access indicate the operator wasShadowPadon ports 80, 8443, and 8080. The IP is identified as high risk due to the historical presence of a ShadowPad controller, and currently hosting a VShell C2 server on port 21083. A single domain,
Products
AlfrescoA text file, alf_cookie.txt contains Alfresco session material for an internal ministry address, adding a document management platform to the operator's list of targets.Apache AmbariIn addition to the Hive scripts, an Apache Ambari command-execution payload, ambari_cmd.json names an internal HDFS DataNode specifically by its hostname. The Ambari payloads target the management layer rather than theApache Hadoopsuo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and Apache Hadoop.Apache HiveServer2The 13 July directory contains over a dozen files related to Apache HiveServer2 exploitation, including multiple Python scripts, compiled Java code. A compressed archive named hive_full_v3.tar.gz, bundled the Thrift andGlassFishGlassFish Console AccessIIS 6.0a Metasploit module (cve2017_7269.rb) targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and path files pointingpolkitthe heap overflow. The exploit affects CentOS 6 and 7 running sudo 1.8.x. CVE-2021-4034 (PwnKit), the polkit pkexec local privilege-escalation vulnerability was also observed on the server.sudoThe operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV).Windows Server 2003targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and path files pointing to the ministry's intranet
Tools
FOFApassword contains the Chinese word "Leishen," which roughly translates to "Thunder God." An API key for FOFA, a Chinese internet asset reconnaissance platform was also observed.HermesThe attack, targeting Thailand's Ministry of Finance (MOF) was largely driven by Hermes, an autonomous AI agent using "YOLO" mode. Additionally, we identified an unreported Go implant the operator refers to as "Hades".Hunt.io Attack CaptureHunt.io Attack Capture archived three open directories on 43.246.208[.]207 during the period of 9 - 13 July 2026, totaling 585 files and 470 MB of attack code and stolen credentials.HuntSQLof the certificate itself rather than its contents. Querying that hash alongside the www common name in HuntSQL returned two additional, related hosts: 118.107.222[.]232 (The Gigabit, Malaysia) and 202.181.27[.]115LinPEASThe Hermes logs found within the three directories capture the agent enumerating ministry hosts, traversing files, and capturing LinPEAS output from an adjacent host.MetasploitFor Windows, a Metasploit module (cve2017_7269.rb) targets CVE-2017-7269, a buffer overflow in the WebDAV service of IIS 6.0, which shipped with Windows Server 2003. Shellcode files with hardcoded directory and pathsuo5on AS132883 (TOPIDC) in Hong Kong. The directories contained exploit code for multiple CVEs, webshells, suo5 HTTP tunnels, custom scripts with hardcoded stolen credentials targeting mail infrastructure and ApacheVShellidentified as high risk due to the historical presence of a ShadowPad controller, and currently hosting a VShell C2 server on port 21083. A single domain, redhatupdating432.dnsrd[.]com resolves to the server, though
Countries
Hong Kongidentified three simultaneous open directories on 43.246.208[.]207, hosted on AS132883 (TOPIDC) in Hong Kong. The directories contained exploit code for multiple CVEs, webshells, suo5 HTTP tunnels, custom scriptsMalaysiathe www common name in HuntSQL returned two additional, related hosts: 118.107.222[.]232 (The Gigabit, Malaysia) and 202.181.27[.]115 (Converged Communications Limited, Hong Kong).ThailandThailand's national CERT and NCSA were notified on July 15, 2026, and acknowledged receipt the same day.