Back to blog
IA & LLMAI agentsmenacetechnique

Hermes AI agent in YOLO mode: the Thai Finance Ministry attack

Published on 2026-07-246 min readCleanIssue

> In short: A threat actor installed the open-source Hermes AI assistant (by Nous Research) on a rented server, switched off the setting that asks for human confirmation before risky actions — a mode called YOLO — and pointed it at Thailand's Ministry of Finance. The agent then ran unattended through the ministry's network: probing hosts for root-escalation paths, hunting file systems, and crawling a folder of staff personnel records back to 2012. The operator left their own attack logs exposed on a web server, where Hunt.io and researcher Bob Diachenko found them.

Why this matters to you

This is not a vulnerability in Hermes. It is a documented feature — YOLO mode — used offensively. The significance for a SaaS audience is that general-purpose AI agents are now practical offensive tooling. The barrier to running an autonomous post-exploitation agent has dropped from "write a custom C2 framework" to "install an open-source assistant and disable a toggle."

If your incident-response playbook assumes human-paced attacker movement, this case is the correction: an agent can probe hosts, escalate, and exfiltrate while the operator is asleep.

What actually happened

The operator configured Hermes to take instructions over Telegram or Slack and run with no confirmation prompts. The agent then performed, on its own:

  • Host enumeration across the ministry network.
  • Privilege-escalation attempts against discovered hosts.
  • Filesystem traversal, including a staff records folder going back to 2012.
  • The agent kept its own logs of every action — and those logs, plus 585 files and 470 MB of attack tooling, were left on a web server with directory listing enabled. That's how the activity surfaced. The ministry has not publicly confirmed a breach.

    The tool is genuinely general-purpose: people install Hermes to manage mail, run chores, and automate work. Nothing about the software is malicious. The offensive use is a configuration choice.

    What this changes in the threat model

    Three shifts are worth internalizing:

  • Pace. An unattended agent can run a full post-exploitation loop in hours, not days. Detection windows that were acceptable against human operators are too slow here.
  • Skill floor. The operator did not need to write the post-exploitation logic. The agent reasoned about it. The skill floor for a capable intrusion drops to "can install software and disable a setting."
  • Logging asymmetry. The agent logs everything it does — which is great for defenders *if* they capture it, and great for researchers *if* the operator slips up (as happened here). On your own infrastructure, agent-style activity is noisier than a careful human — if you're looking for it.
  • What to do

  • Update your detection假设. Treat anomalous autonomous-agent-style activity — rapid scripted probing, repetitive filesystem walks, credential-guessing at machine pace — as a detection category, not just "an unusual user." Endpoint telemetry that flags fast, repetitive, multi-host patterns matters more than it used to.
  • If you let employees use AI agents internally, document and restrict YOLO-style modes. "Disable confirmation prompts" should be a privileged action, logged and reviewable.
  • Watch for exposed logs. The case was uncovered because the operator self-doxed. Public-facing servers with directory listing or exposed object storage remain a leading way intrusions surface. Scan your own exposure regularly.
  • For IR retainers and breach response, add an "agent-assisted intrusion" scenario. The evidence shape is different: structured agent logs, command traces, repeating reasoning patterns.
  • The bigger picture

    The Hermes case is a preview of offensive AI in 2026–2027. The capability is here, it is open-source, and the barrier is configuration rather than development. For defenders, the response is not to ban AI — it is to assume the attacker's loop is now faster and more autonomous, and to size detection, logging, and response to that pace.

    Building HR, payroll, or recruiting software? CleanIssue performs security audits for HR SaaS in real-world conditions, no source code access needed. For a first read of your exposure, start with an external review of your application.

    Sources

    Related services

    If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

    Need an external review of your HR SaaS?

    Share your product, stack, and client context. We will come back with the right review scope.

    Discuss your audit