Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

103.97.0.57

TLP:CLEAR
Active

IPv4 Address

Description

Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Pattern Type
STIX
Confidence
75%
Valid From
Jul 24, 2026 02:00
Total Sightings
0
Added
Jul 24, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 103.97.0.57

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.