Hermes AI agent used to automate attack on Thai Finance Ministry

2026-07-24T19:23:33Zfe517791361fd9e8262f5a7f41d3e00d755c5a8aa241cc5869a666e279e899d2
ai-automationai-enabled-attackai-profilingchick-fil-aclop-ransomwarecredential-stuffingdata-breachdns-hijackdolphin-xfake-appflexplmhermes-agenthotel-wifilaundry-bearmaintenance-bugmalvertisingmicrosoft-365-phishingmicrosoft-outagenotepad++-plugin-abuse','lunchpoke'ratsectopratwindchillyolo-modezero-clickzimbra

What happened

A set of Bleeping Computer stories (23–24 Jul 2026) highlights rising use of AI and automation in attacks (Hermes AI agent in "YOLO" unattended mode, Dolphin X RAT with AI profiling), active credential-theft campaigns (hotel Wi‑Fi DNS hijacks redirecting users to fake Microsoft 365 logins, malvertising pushing a fake Claude app that delivers SectopRAT), and multiple high-impact intrusions and outages (Microsoft 365 outage caused by a maintenance bug, Clop targeting Internet‑exposed PTC Windchill/FlexPLM, Zimbra zero‑click exploit leveraged by Russian group Laundry Bear). Other notable items: a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fe517791361fd9e8262f5a7f41d3e00d755c5a8aa241cc5869a666e279e899d2
Enrichment time
2026-07-24T19:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hermes AI agent used to automate attack on Thai Finance Ministry · Baitaphish