Malware, Threat Intelligence

AI assistant used in cyberattack on Thailand’s Ministry of Finance

An open-source AI assistant named Hermes was used in a cyberattack targeting Thailand's Ministry of Finance, compromising sensitive personnel data and internal systems. The attack involved an operator configuring the AI assistant to bypass security checks and autonomously navigate the ministry's network, based on information published by The Hacker News.

The attacker utilized the Hermes AI agent, installed on a rented server, by disabling its safety features that require human approval for risky commands. This allowed the AI to independently scan the Ministry of Finance's network for vulnerabilities, access staff personnel records dating back to 2012, and attempt to gain root access. The operator also planted a web shell and scripts targeting internal Hadoop systems, along with stolen mailbox passwords. A key vulnerability exploited was the default configuration of HiveServer2, which accepted any password. The AI's actions included running privilege escalation scripts like LinPEAS and crawling file systems. The operator's logs, containing attack tooling, were inadvertently left exposed on a web server. While the AI performed automated tasks, the human operator was responsible for initial reconnaissance and targeting. Thailand's national CERT and cybersecurity agency were notified, but no public statement was made as of July 24. The incident highlights the potential misuse of AI tools in cyberattacks when configured without proper safeguards, and the importance of securing default configurations in systems like Hadoop.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds