Attackers used Hermes, an open-source AI agent running in unrestricted "YOLO mode," to conduct espionage operations against Thailand's Ministry of Finance. Researchers also discovered an unreported Go-based implant called Hades in the compromised infrastructure.
Threat actors used the open-source Hermes AI agent in unattended 'YOLO' mode to automate post-exploitation activities during a breach of Thailand's Ministry of Finance. The attack also involved staging of the Hades implant for further system compromise.