Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
Hunt.io uncovered a cyber-espionage attack on Thailand’s Finance Ministry using Hermes AI agent and Hades malware for reconnaissance and persistence. Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers […]

Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered.
The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown.
Related breach coverage
- Hackers used autonomous AI agent to spy on Thailand's finance ministry2026-07-27
Hackers used an autonomous artificial intelligence agent to carry out a cyber-espionage campaign against Thailand's Ministry of Finance, researchers discovered.
- Claude Code and DeepSeek Powered Chinese Cyber Espionage Campaign2026-07-16
Chinese actors used Claude Code and DeepSeek to automate attacks that breached government systems and targeted financial firms. Hunt.io researchers stumbled onto an active intrusion campaign in June 2026 while pivoting on known TencShell command-and-control infrastructure. A single HTTP header fingerprint on port 1111 led them to 13 Hong Kong-based servers and, on one of […]
- Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network2026-07-18
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented […]
- New Crypter-as-a-Service Cruciferra Fuels Stealthy Malware Attacks Worldwide2026-07-28
Proofpoint uncovered Cruciferra, a crypter-as-a-service that helps hackers evade antivirus and deliver malware in multiple campaigns. Proofpoint’s research team traced a wave of income-tax-themed lures targeting Indian taxpayers, tax professionals, and corporate finance teams back to a crypter service called Cruciferra, and the tool turns out to be shared infrastructure used across multiple unrelated criminal […]
