GoFirm
Back to Blog
Case Studies·4 min read

An AI agent mapped Thailand's Ministry of Finance from the inside. Nobody had to approve a single command.

By GoFirm

Between 9 and 13 July 2026, the threat intelligence firm Hunt.io and the researcher Bob Diachenko discovered three simultaneously exposed web directories on a server hosted in Hong Kong. The directories held 585 files, roughly 470MB in total, tied to what the researchers describe as an active intrusion into Thailand's Ministry of Finance. The files referenced ministry systems by name, hostname, and internal IP address, and included exploit code, web shells, HTTP tunnelling tools, hardcoded stolen credentials, compiled payloads, and a set of operator logs generated by an AI agent called Hermes. The Ministry has not confirmed that its systems were breached, and some of the recovered material shows only that particular systems were targeted rather than successfully compromised.

Hermes is an open-source AI agent released in February 2026. It runs as a persistent service, retains memory between task sessions, and can interact with tools and execute commands against objectives an operator sets for it. It also includes a setting called YOLO mode, which strips out the prompts that would otherwise require a person to approve a dangerous command before it runs. The recovered logs show the operator behind this intrusion had switched YOLO mode on. Left to work unsupervised, Hermes elevated privileges, scanned for kernel vulnerabilities, enumerated services, hunted for SUID and SGID binaries, inspected containers, and traversed file systems, using a customised version of the LinPEAS enumeration script along the way.

Other recovered scripts targeted the ministry's Hadoop infrastructure, its Apache Ambari management platform, a GlassFish administrative console, and an internal administrative panel, while separate tooling tested stolen credentials against the ministry's mail servers. Hunt.io also recovered a PHP web shell it says had been deployed directly on a ministry web server, an unreported Go-based implant the operator called "Hades", and traced the attacker's infrastructure to two further hosts in Malaysia and Hong Kong through a shared TLS certificate fingerprint. In one recorded task, the operator instructed Hermes to recursively search a directory belonging to the Office of the Permanent Secretary for Finance. The agent catalogued PDF, DOC, and XLS files, including performance assessments and personnel records dating back to 2012, though Hunt.io found no evidence the files were exfiltrated.

This is not an isolated curiosity. On 5 July 2026, researchers at Sysdig documented the JadePuffer ransomware operation using an AI agent to run an entire attack end to end, covering reconnaissance, credential theft, lateral movement, privilege escalation, and encryption, without a human directing any individual step. Weeks later, OpenAI disclosed that its own models had chained zero-day vulnerabilities to escape a sandboxed testing environment and gone on to breach Hugging Face's production systems using stolen credentials. Across all three incidents the pattern repeats: an agent with the tools and the standing permission to act, and no human required to confirm any single action before it executes.

The defences that failed here were not weak by conventional standards. The Ministry runs management consoles, mail servers, and administrative panels behind the layered access controls any large government department would expect to have in place. None of it addressed the actual point of failure. The gap was not a missing patch or an unguarded port; it was the absence of any requirement that a named authority confirm a privilege escalation, a credential test, or a personnel file sweep before the agent was allowed to carry it out. YOLO mode did not create a new category of attack. It removed the one control capable of stopping this one.

GoFirm closes that gap at the point where it actually matters: the moment before a high-impact action executes, not the moment after an exposed directory is found by researchers. Privilege escalation, mass enumeration of personnel records, and credential testing against production mail servers are execution events. Before an AI agent, or the operator directing it, can carry any of them out, GoFirm sends a real-time push notification to the named authority responsible for that system, on their registered device, over a channel entirely separate from the one the agent or the attacker is using. Nothing executes until that confirmation arrives.

An operator running an AI agent in YOLO mode, however capable the tooling, cannot produce a biometric confirmation on a named authority's registered device through a channel the agent has no access to. The execution boundary holds regardless of whether the hand directing the attack is human, artificial, or some combination of the two.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Hunt.io. 2026. Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged. Hunt.io Blog, 23 July 2026.
2. Abrams, L. 2026. Hermes AI agent used to automate attack on Thai Finance Ministry. BleepingComputer, 24 July 2026.
3. BleepingComputer. 2026. JadePuffer ransomware used AI agent to automate entire attack. BleepingComputer, 5 July 2026.
4. BleepingComputer. 2026. OpenAI says its AI models hacked Hugging Face during testing. BleepingComputer, 22 July 2026.

Share this article