Agentic AI is Changing the Cyberattack Game: When the Hermes AI Agent Begins Performing Operational Tasks Previously Handled by Humans

What Happens When AI Begins Acting as an Operational Assistant in Cyberattacks?

AI is evolving from a tool used primarily for content generation and data analysis into a system09 capable of receiving objectives, operating tools, interpreting results, and continuously carrying out tasks within the permissions it has been granted.

In the context of cyberattacks, the key issue is no longer limited to how effectively AI can write code or generate phishing messages. When AI is connected to operating systems, tools, and data, attackers can delegate certain tasks to an AI agent without manually controlling every command.

AI does not fundamentally change every principle of cyberattack operations. However, it can reduce the time spent on repetitive tasks, lessen the burden of reviewing and interpreting results step by step, and enable post-exploitation activities to proceed more quickly and continuously.

The central concern is that AI can reduce both the time and human resources required by attackers, from system reconnaissance and privilege-escalation analysis to maintainingaccess to a target environment.

In this article, BMSP examines the role of Agentic AI in cyberattack operations through the Hermes AI Agent case. It also explores the urgent issues organizations should review under Thailand’s Cybersecurity Act B.E. 2562 (2019), together with six hypothesized structural factors that may leave organizations unprepared for this emerging form of threat.

Table of Contents

The Hermes AI Agent Case: How Was AI Used?

On July 24, 2026, The Hacker News and BleepingComputer reported that an operator had used Hermes, an open-source AI agent, to support an operation targeting systems associated with a Thai government agency.

According to the reports, the operator installed Hermes on an external server and enabled YOLO Mode, also referred to as Unattended Mode. This configuration allowed the agent to execute commands and continue analyzing results without waiting for human approval before every potentially risky action.

Hermes was not developed as a hacking tool, and the reported incident did not result from a vulnerability in Hermes itself.

The key issue was that the operator connected the AI agent to attack-related tools and information, granted it permission to execute commands, and enabled a mode that reduced human oversight before each action.

The Operator Appeared to Have Access Before Deploying Hermes

The publicly reported evidence suggests that the operator had likely obtained access to parts of the target environment before Hermes was introduced.

The evidence reportedly included:

  • A web shell placed on a web server
  • Scripts referencing internal systems
  • Account credentials embedded in a script used to test an email system


However, the available information did not establish how the operator obtained initial access to the environment.

As of the publication date of the reports, the relevant Thai government agency had not publicly confirmed the details of the incident.

What Did Hermes Do After the Initial Compromise?

After the operator had gained access to the environment, Hermes was reportedly used to assist with post-exploitation activities.

The key activities identified in the logs included:

  • Examining Linux systems for possible privilege-escalation paths
  • Running LinPEAS and interpreting its output
  • Searching for files and binaries with elevated privileges
  • Exploring services and file-system structures
  • Inspecting containers and internal systems
  • Recursively enumerating web directories
  • Interpreting results and selecting what to investigate next


Hermes could therefore receive an objective, execute tools, interpret the results, analyze the findings, and continue working without requiring human approval at every stage.

The directory enumeration identified PDF, DOC, and XLS files, including office documents, performance evaluation records, and files associated with personnel dating back to 2012.

However, the disclosed evidence only confirmed that the agent enumerated directories and generated file listings. It did not establish that the agent opened and read the contents of every document.

The reviewed dataset also did not contain evidence that the files were exfiltrated from the network. However, the absence of such evidence should not be interpreted as confirmation that no data exposure occurred.

AI Did Not Conduct the Entire Attack Independently

The incident should not be described as Hermes independently selecting the Thai government agency as a target or carrying out the entire attack from initial access to completion.

The disclosed information does not show that Hermes:

  • Discovered a new vulnerability
  • Obtained initial access independently
  • Selected the target on its own
  • Conducted the entire attack without human involvement


Human operators remained responsible for activities requiring knowledge of the target, including:

  • Selecting the organization and systems to target
  • Preparing target-specific information and tools
  • Developing scripts and credential lists
  • Defining objectives for the agent
  • Making key operational decisions


Hermes was used to accelerate repetitive and continuous tasks, such as executing tools, reviewing results, determining what should be investigated next, and issuing subsequent commands without requiring constant human supervision.

A more accurate description than saying that “AI hacked the system by itself” would therefore be:

Attackers used an AI agent to support post-exploitation activities, allowing the agent to carry out selected tasks continuously without requiring human approval for every command.

In technical terms, this can be described as: AI-assisted unattended post-exploitation

What Organizations Should Learn from the Incident

The significance of the Hermes case does not lie in the technical complexity of the commands executed by the agent. Most of the commands and tools involved were already available to experienced human operators.

What changed was that the attacker no longer needed to manually supervise every individual step.

An AI agent can perform repetitive tasks, interpret scan results, and continue working. This can reduce the time attackers require to explore systems, assess privilege-escalation opportunities, and search for information within an environment.

As attackers operate more quickly, the window available for organizations to detect and stop an intrusion may become shorter, particularly for organizations that review logs daily or weekly or rely on users to report suspicious activity.

The incident demonstrates that organizations should not depend solely on firewalls, VPNs, or other perimeter-based controls. They must also be able to detect abnormal behavior, control access privileges, restrict lateral movement, and respond to incidents continuously.

The information presented in this case study is based on threat intelligence reporting by The Hacker News and BleepingComputer. It should not be interpreted as the result of an official investigation by the Thai government agency concerned.

What Has Changed: Speed and the Operating Model

In a traditional cyberattack, the attacker must repeatedly issue commands, review the output, analyze the information, and decide what to do next.

With an AI agent, this process can shift from command-by-command control to objective-based delegation.

For example, an operator may instruct an AI agent to:

  • Determine whether privilege escalation may be possible
  • Search for files that may contain credentials or sensitive information
  • Explore services accessible from the current system
  • Interpret assessment results and recommend the next step
  • Repeat similar activities across multiple systems or files
  • Consolidate findings for further human decision-making

AI does not guarantee that every action will succeed. However, it can reduce the time required to interpret results, perform repetitive work, and make lower-level operational decisions.

The result is a narrower window in which organizations can detect and stop an attack, particularly where logs are reviewed only periodically or action is delayed until users report a problem.

Where Can AI Assist Attackers?

Across the broader cyberattack lifecycle, an AI agent may assist with activities such as:

  • Discovering systems and services exposed to the internet
  • Analyzing operating systems, software, and vulnerabilities
  • Searching for accounts, passwords, tokens, or other secrets
  • Assessing possible privilege-escalation paths
  • Identifying opportunities to move to other systems
  • Establishing or identifying methods for maintaining access
  • Discovering and categorizing sensitive information
  • Supporting system control or preparing information for exfiltration


These capabilities depend on the tools, permissions, information, and instructions provided to the AI.

They do not mean that an AI agent can bypass every security control or operate without limitations.

However, when an organization has weak configurations, shared privileged accounts, overly permissive internal connectivity, or insufficient behavioral monitoring, AI can help attackers connect multiple weaknesses into a viable attack path more quickly.

Urgent Actions Under Thailand’s Cybersecurity Act B.E. 2562 (2019)

The transition from human-operated attacks to AI-assisted or Agentic AI-enabled attacks does not mean that organizations must wait for new regulations before taking action.

Thailand’s Cybersecurity Act B.E. 2562 (2019) already requires relevant organizations to prevent, respond to, and reduce the risks arising from cyber threats.

As attack operations become faster, organizations should urgently review whether their controls, plans, designated personnel, and incident-reporting processes can function effectively during a real emergency.

Fundamental Obligations of Relevant Organizations

Section 44: Standards, Risk Assessments, and Response Plans

Government agencies, regulatory or supervisory bodies, and CII entities must develop their own cybersecurity codes of practice and standards in alignment with national policies and plans.

At a minimum, these codes of practice must include:

  • A cybersecurity audit and risk-assessment plan conducted at least once a year
  • A cyber-threat response plan
Section 45: Prevention, Response, and Risk Reduction

Organizations are required to implement measures to prevent, respond to, and reduce cyber risks in accordance with the applicable codes of practice and standards.

Where an organization is unable to implement the required measures, the relevant Office may provide personnel or technological assistance upon request.

Section 46: Executive-Level and Operational-Level Coordinators

Organizations must notify the relevant Office of the names of executive-level and operational-level personnel designated to coordinate cybersecurity matters.

In practice, these coordinators may be referred to as Cyber Focal Points. However, the terminology used directly in the Act refers to executive-level and operational-level coordinating personnel.

The appointment of coordinators, the performance of risk assessments, and the preparation of incident-response plans are therefore not merely optional good practices. They are important components of compliance with legal obligations.

Additional Obligations for Designated CII Entities

An organization’s participation in a critical sector does not automatically establish that it has been formally designated as a CII entity.

CII status must be determined through the applicable designation process and criteria.

*CII stands for Critical Information Infrastructure.

For organizations formally designated as CII entities, the Act establishes additional obligations.

Section 54

CII entities must conduct cybersecurity risk assessments and security audits at least once a year.

A summary of the results must be submitted to the relevant Office within 30 days after the assessment or audit has been completed.

Section 56

CII entities must establish mechanisms or procedures for monitoring cyber threats and cybersecurity incidents.

They must also participate in cybersecurity readiness exercises organized by the relevant Office.

Section 57

When a cyber threat has a significant impact on the systems of a CII entity, the organization must report the incident to the relevant Office and its regulatory or supervisory body and respond in accordance with the applicable procedures.

These obligations demonstrate that CII preparedness must include risk assessment, monitoring, readiness testing, and incident reporting. It cannot rely solely on the deployment of preventive security tools.

Obligations When a Cyber Threat Occurs or is Expected

Section 58 requires government agencies and CII entities to act promptly when a cyber threat occurs or is reasonably expected to affect an information system under their responsibility.

The organization must:

  • Examine the relevant computer data, systems, and surrounding circumstances
  • Assess whether a cyber threat has occurred or is expected to occur
  • Implement measures to prevent, respond to, and reduce the associated risks
  • Notify the relevant Office and the applicable regulatory or supervisory body


Where an organization or individual encounters obstacles in preventing, responding to, or reducing the risk, assistance may be requested from the relevant Office.

Limitations in staffing, technology, or budget should therefore lead to a request for support. They should not become a reason for failing to establish controls, investigate an incident, or report a cyber threat.

What Executives in Every Organization Should Begin Reviewing

Executives should determine whether the following elements are in place and can function effectively:

  • Designated executive-level and operational-level coordinators
  • An inventory of critical systems and their owners
  • An up-to-date cybersecurity risk assessment
  • A cyber-threat response plan
  • Monitoring and suspicious-activity investigation processes
  • Criteria for escalating and reporting incidents
  • Contact channels for the relevant Office, regulators, and service providers
  • Procedures for preserving evidence
  • Procedures for isolating systems, containing incidents, and restoring services
  • Exercises involving executives and mission or business owners


Documentation alone is not sufficient.

An organization may have a formal response plan, but the plan will be ineffective if no one has the authority to make decisions, no one is monitoring alerts, or the procedures have never been tested under conditions in which primary systems are unavailable.

BMSP Identifies 6 Hypothesized Structural Factors That May Leave Organizations Unprepared for Agentic AI

The following six factors represent BMSP’s preventive analysis based on lessons from the reported incident and risks that organizations should review.

They should not be interpreted as investigative findings that the government agency mentioned in the reporting suffered from all six weaknesses.

1. Overreliance on Perimeter Security

Firewalls, VPNs, web application firewalls, and other perimeter-security controls remain essential.

However, their presence should not create the assumption that every system inside the network can be trusted.

Once an attacker bypasses the first layer of defense—through a vulnerability, stolen credentials, a configuration error, or third-party access an internal environment based on implicit trust may allow the attacker to explore additional systems and access other services rapidly.

Organizations should:

  • Adopt an Assume Breach approach
  • Enforce multifactor authentication
  • Apply the principle of least privilege
  • Segment networks according to business function and criticality
  • Continuously verify access in accordance with Zero Trust principles
2. Inadequate Identity and Privilege Management

A single set of compromised credentials can become the starting point for extensive damage when the associated account has excessive privileges or access to multiple systems.

Common weaknesses include:

  • Shared administrator accounts
  • Service accounts with excessive privileges
  • Accounts belonging to former employees or contractors that remain active
  • Passwords or API keys embedded in scripts
  • The same account being used for production, backup, and administration systems
  • The absence of MFA for remote access or cloud administration

Organizations should separate standard user accounts from administrative accounts, eliminate shared administrator accounts, rotate passwords and secrets, implement Privileged Access Management where appropriate, and periodically review and certify access privileges.

3. Overly Permissive Internal Network Access

If user, server, database, backup, and management networks can communicate without sufficient restrictions, a compromised user device or web server may become a pathway to other critical systems.

Organizations should:

  • Segment network zones according to function
  • Separate backup and management networks from normal production environments
  • Restrict east-west traffic
  • Control communication between network segments
  • Avoid exposing management interfaces directly to the internet
4. Detection Still Relies More on IOCs Than Behavioral Analytics

IP addresses, domains, and file hashes can be changed rapidly.

Detection that relies only on Indicators of Compromise may fail to identify new tools or newly deployed infrastructure, even when the underlying attack behavior remainsunchanged.

The Hermes case also demonstrates that an endpoint may see only shell commands and common tools. The command line may not clearly indicate whether the activity was initiated by a human operator or an AI agent.

Organizations should therefore prioritize behavioral detection, including:

  • Rapid enumeration of multiple accounts or systems
  • Searches for credential or secret files
  • Privilege-escalation attempts
  • Creation of scheduled tasks or cron jobs
  • Remote administration activity that deviates from normal patterns
  • Connections from a web server to unrelated internal systems
  • Lateral movement between systems
  • Unusually large outbound data transfers
  • Periodic communication with command-and-control infrastructure
5. Logs Are Collected, but Continuous Monitoring and Incident Readiness Are Lacking

The presence of logs does not mean that an organization is actively monitoring its environment.

Logs provide limited value if no one reviews them, appropriate alerts have not been configured, responsibilities are unclear, or escalation procedures have not been established.

When AI can accelerate repetitive operations and interpret results quickly, an organization’s Mean Time to Detect and Mean Time to Respond may be too long to stop the attack or contain the damage.

Organizations should:

  • Assign clear responsibility for reviewing alerts
  • Establish emergency reporting channels
  • Develop incident-response playbooks
  • Conduct exercises involving executives, system owners, legal teams, communications teams, and external service providers
6. Executives Still View Cybersecurity as Solely an IT Responsibility

Many cybersecurity risks cannot be addressed by the IT department alone.

They involve budgets, procurement, information ownership, contractors, service continuity, and enterprise-level risk acceptance.

When cybersecurity is treated only as a support function, organizations may lack accountable owners, decision-making authority, and the ability to address cross-functional risks.

Executives should therefore integrate cybersecurity into:

  • Enterprise Risk Management
  • Business Continuity
  • Internal Control
  • Digital Governance
  • Procurement Governance
  • System-owner accountability

The Impact Is Not Limited to IT Systems

A compromise involving a government agency or other organization may result in:

  • Disruption of public or customer services
  • Exposure of citizen, customer, or internal information
  • Modification, destruction, or misuse of critical systems
  • Economic losses
  • Reduced public or customer confidence
  • The organization’s systems being used as a platform for attacks against others
  • Disruption to critical missions or national security


For a CII entity, the impact should not be measured only by the number of affected devices.

The organization must also consider whether critical services can continue operating and how citizens, customers, or dependent organizations may be affected.

The Act also establishes potential liability in certain circumstances, including an unjustified failure by a CII entity to report an incident or failure to comply with legally issued orders during serious or critical cyber-threat situations.

However, the occurrence of a cyberattack does not automatically create legal liability for the organization or its executives.

Any assessment of liability must consider the organization’s legal status, applicable obligations, relevant orders, actions or omissions, and the specific facts of the incident. Legal counsel should therefore assess each case individually.

Key Takeaway

Agentic AI does not make the fundamental principles of cybersecurity obsolete.

However, it gives organizations with weak identity controls, flat internal networks, delayed detection, and unclear governance less time to respond.

The question organizations should consider is:

If an attacker gains access, how quickly can the organization detect the intrusion, restrict lateral movement, contain the damage, and restore critical services?

The goal is not to guarantee that an organization will never be attacked.

The goal is to make the organization harder to compromise, faster at detecting incidents, more capable of containing damage, and able to restore critical operations securely and reliably.

Read Next: A Deep Dive into Defending Against Agentic AI: A 30-60-90-Day Plan for Organizations and CII Entities

References

For cybersecurity solutions tailored to your organization, contact BMSP.

Contact BMSP

Contact BMSP to discuss practical cybersecurity solutions for your organization.

Share

Related Content

Get in touch with us. We’re here to assist you.

08. Home Bottom (EN)

Learn how we helped 100 top brands gain success