An attacker installed the open-source Hermes AI assistant on a rented server, disabled its permission-requesting YOLO mode, and directed it at Thailand’s Ministry of Finance. The agent autonomously scanned for kernel vulnerabilities, enumerated file systems, and crawled a folder containing personnel records dating back to 2012. Threat intelligence firm Hunt.io and researcher Bob Diachenko discovered the agent’s logs and 470 MB of attack tooling on an exposed web server. The operator used custom scripts targeting the ministry’s Hadoop cluster, exploiting the default NONE authentication mode in HiveServer2 to deploy a malicious Java add-on (HiveCmd.jar) for remote code execution. Additional staged tools included a previously undocumented Go implant called Hades (62 copies), exploit code for older flaws (polkit, sudo, IIS 6.0), and a hidden web shell. The attacker’s SSH session originated from Hong Kong (103.97.0[.]57), and artifacts suggest a Chinese-speaking operator. No data exfiltration was confirmed. Thailand’s national CERT and cybersecurity agency were notified on July 15 but had not publicly responded by July 24.
CVEs: CVE-2026-31431, CVE-2026-43284, CVE-2026-43500, CVE-2026-43503, CVE-2021-4034
Attack groups: Chinese-speaking threat actor
Malware: ShadowPad, Hades, HiveCmd.jar, LinPEAS
Companies: Hunt.io, Nous Research, Apache, Cloudera, The Hacker News
Products: Hermes AI Agent, HiveServer2, VShell, FOFA, GlassFish
Original source: thehackernews.com