Agentic threat actors
Incidents involved as Deployer
Incidente 15784 Reportes
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database
2026-07-01
Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.
MásIncidente 16464 Reportes
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
2026-07-01
From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.
MásIncidente 16694 Reportes
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
2026-07-09
Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.
MásIncidente 16613 Reportes
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
2026-04-08
Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.
MásEntidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
Entidades relacionadas
Privacy
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Threat actors
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
hackers
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
AI agent system deployers
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Nous Research
Incidents involved as Developer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
National security and intelligence stakeholders
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Information security
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Governments
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Government agencies
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Hermes Agent
Incidents implicated systems
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network