Researchers reported an active espionage intrusion targeting Thailand’s Ministry of Finance, tied to exposed attacker infrastructure at 43.246.208[.]207 and additional linked hosts in Hong Kong and Malaysia. The operation used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate ministry systems, map internal services, and assess privilege-escalation paths, while a previously undocumented cross-platform Go implant dubbed Hades was staged to maintain persistence on both Windows and Linux systems. Investigators also linked a VShell C2 server and the domain redhatupdating432.dnsrd.com to the activity.
Recovered artifacts showed targeting of ministry administrative panels, mail infrastructure, Apache Hadoop and HiveServer2 environments, Apache Ambari, GlassFish, Alfresco, and internal document systems. The exposed directories contained exploit code, web shells, stolen credentials, credential-testing scripts, and Linux and IIS exploitation or privilege-escalation modules, while Hades reportedly supported command and control, file transfer, proxying, and screen capture. Investigators said the evidence indicates compromised internal access, though no data exfiltration had been confirmed at publication time, and assessed with low-to-moderate confidence that the operator was a Chinese-speaking or Sinophone threat actor based on infrastructure history, Chinese-language indicators, and use of FOFA.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-30, Unit 42 published an investigation describing a Chinese-speaking threat actor using DeepSeek via the Hermes Agent framework and Telegram to autonomously enumerate targets, identify vulnerabilities, and attempt exploitation. The report also disclosed confirmed successful exploitations against Citrix NetScaler, Marimo notebook, Apache Tomcat, and Windows IKE VPN targets, including persistent targeting of a Malaysian government entity, after the operation was exposed by an accidentally opened HTTP file server.
The published investigation assessed with low-to-moderate confidence that the operation was conducted by a Chinese-speaking or Sinophone threat actor. The assessment was based on infrastructure history, Chinese-language indicators, ShadowPad-related infrastructure history, and use of FOFA.
On 2026-07-23, Hunt.io and researcher Bob Diachenko published a technical investigation describing the ongoing operation. The report tied exposed staging infrastructure on 43.246.208.207, additional linked hosts, a VShell C2 server, and the domain redhatupdating432.dnsrd.com to the activity.
The investigation identified a previously undocumented cross-platform Go implant called Hades that provided persistence and command-and-control capabilities on Windows and Linux hosts. Reported functions included file transfer, proxying, and screen capture.
Recovered logs and scripts showed the operators used the open-source Hermes autonomous AI agent in unattended "YOLO" mode to enumerate the ministry network and assess privilege-escalation paths. The tooling was used against exposed ministry-facing services during the intrusion.
Researchers documented an ongoing espionage intrusion targeting Thailand's Ministry of Finance in July 2026. Artifacts indicated compromised access to multiple internal systems, including administrative panels, mail infrastructure, Hadoop/HiveServer2, Ambari, GlassFish, and document systems.
Hunt.io and Bob Diachenko notified ThaiCERT and Thailand's National Cyber Security Agency about the suspected intrusion affecting Thailand's Ministry of Finance. According to the report, both organizations acknowledged receipt on the same day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
14 references tracked. Mallory keeps watching after this page renders.
unit42.paloaltonetworks.com
Open sourcemeetcyber.net
Open sourcedarkreading.com
Open sourcetherecord.media
Open sourcehunt.io
Open sourcecyberveille.ch
Open sourcehermes-agent.org
Open sourcecode.claude.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.