IPv4 Address
Between July 9-13, 2026, three exposed directories on a Hong Kong server revealed an ongoing cyber espionage operation targeting Thailand's Ministry of Finance. The attack leveraged Hermes, an autonomous AI agent operating in unattended YOLO mode, alongside a custom Go-based implant called Hades. Recovered files included exploit code for multiple vulnerabilities, webshells, stolen credentials, and purpose-built scripts targeting MOF Hadoop infrastructure, mail systems, and GlassFish consoles. The AI agent autonomously enumerated ministry networks using LinPEAS, traversed files, and assessed privilege escalation paths. Infrastructure analysis linked multiple Hong Kong and Malaysian servers through TLS certificates and hardcoded C2 addresses. Chinese-language indicators and historical ShadowPad/VShell presence suggest probable Chinese-speaking attribution, though initial access methods remain undetermined.
No sightings recorded yet