LIVE FEED
ATLAS OWASP CRITICAL Active exploitation · Immediate action required RELEVANCE ▲ 8.5

Hermes AI Agent Used in Espionage Attack on Thai Finance

TL;DR CRITICAL
  • What happened: Attackers weaponised the Hermes open-source AI agent in YOLO mode to spy on Thailand's Ministry of Finance.
  • Who's at risk: Government ministries and public-sector organisations are most exposed, as autonomous AI agents can operate persistently inside networks with minimal human oversight.
  • Act now: Audit and restrict deployment of open-source agentic AI tools within sensitive network environments · Enforce strict guardrails and human-in-the-loop approval for any autonomous agent actions touching government infrastructure · Monitor for anomalous autonomous process execution patterns indicative of AI agent activity
Hermes AI Agent Used in Espionage Attack on Thai Finance

Overview

A confirmed espionage campaign targeting Thailand’s Ministry of Finance has introduced a significant new dimension to the threat landscape: the use of an autonomous open-source AI agent as the primary attack tool. Threat actors deployed Hermes, an open-source agentic AI framework, configured in its unrestricted ‘YOLO mode’ — a setting that removes confirmation prompts and allows the agent to execute tasks autonomously without human approval at each step. The incident marks a notable escalation in the operational use of AI agents by adversaries against government targets.

Technical Analysis

Hermes is an open-source autonomous agent framework designed to complete multi-step tasks by chaining LLM reasoning with tool calls — including web browsing, file system access, code execution, and API interactions. In standard operation, Hermes prompts the user for confirmation before executing potentially destructive or sensitive actions. YOLO mode disables these confirmation gates entirely, allowing the agent to proceed through a full task chain autonomously.

In this attack, the adversaries appear to have leveraged YOLO mode to enable the agent to conduct reconnaissance, exfiltrate data, and potentially move laterally within Ministry of Finance systems without requiring an operator to approve each action in real time. This dramatically reduces the operational overhead for attackers and increases the speed and stealth of the intrusion. The use of an open-source tool also lowers the barrier to attribution and acquisition.

The attack chain likely involved:

  • Initial access via conventional means, followed by agent deployment
  • Autonomous reconnaissance using Hermes’s tool-use capabilities
  • Data collection and exfiltration driven by LLM-generated task planning
  • Minimal human operator involvement during execution phases

Framework Mapping

FrameworkTechniqueRationale
ATLASAML.T0047 – ML-Enabled Product or ServiceHermes is an LLM-powered product used as the attack vehicle
ATLASAML.T0054 – LLM JailbreakYOLO mode functionally removes safety constraints, analogous to jailbreaking
ATLASAML.T0057 – LLM Data LeakageAgent likely accessed and exfiltrated sensitive government data
OWASPLLM08 – Excessive AgencyCore risk: agent granted unbounded autonomous action capability
OWASPLLM06 – Sensitive Information DisclosureGovernment financial data exposed through agent-driven exfiltration

Impact Assessment

The direct victim — Thailand’s Ministry of Finance — faces potential exposure of sensitive fiscal, budgetary, or policy data. More broadly, this incident signals that autonomous AI agents are now operational tools in state-sponsored espionage, not merely theoretical risks. Any organisation deploying or exposed to agentic AI frameworks faces an expanded attack surface, particularly when those frameworks can be repurposed by adversaries with minimal modification.

Open-source availability of tools like Hermes means the barrier to replicating this attack is low, increasing the likelihood of copycat campaigns.

Mitigation & Recommendations

  1. Restrict agentic AI deployment: Open-source agent frameworks should be banned or tightly sandboxed within government and critical infrastructure networks.
  2. Enforce human-in-the-loop controls: Any legitimate agentic AI deployment should require explicit human approval for file access, network calls, and data exports.
  3. Monitor for agent-like behaviour: Implement behavioural detection for sequential, rapid, LLM-patterned tool invocations that suggest autonomous agent activity.
  4. Threat-hunt for Hermes IOCs: Security teams should develop signatures for Hermes agent artefacts, logs, and network patterns.
  5. Review open-source AI tool policies: Establish governance frameworks for which AI agent tools are permitted in sensitive environments.

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.