An unidentified threat actor assessed by Hunt.io with low-to-medium confidence to be Chinese-speaking or fluent in Chinese. The actor deployed a Hermes AI agent in YOLO mode for post-exploitation against the Thai Ministry of Finance. Artifacts include a web interface password containing the Chinese word 'Leishen' (thunder god) and a FOFA key.