News Room
16
Share
AI-Driven 'Hermes' Harness Automates Ransomware Exploitation for $4 per Attack
criticalThreat Intelligence

AI-Driven 'Hermes' Harness Automates Ransomware Exploitation for $4 per Attack

A newly discovered AI agent named Hermes, utilizing DeepSeek-V4-Pro, has been identified automating full-chain ransomware attacks against global enterprises for minimal token costs.

03 September 2026Last updated 03 September 20265 min readCybernews Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Cybercriminal
Geography:
Global
Confidence:
High Confidence
Source:
Cybernews Intelligence
Read Time:
5 min

Executive Summary

Over the last 48 hours, the ransomware landscape has shifted from manual intrusion to high-velocity automation. Intelligence reports from September 2-3, 2026, reveal a surge in successful compromises targeting diverse sectors, including South Korean automotive manufacturer iwin, U.S. auto financier GSAC, and the international law firm Holland & Knight. The most significant development, however, is the discovery of an exposed command-and-control (C2) server belonging to an affiliate of 'The Gentlemen' ransomware gang. This server contained 3.1 terabytes of exfiltrated data and evidence of a fully automated AI exploitation harness named 'Hermes,' which reduces the cost of a sophisticated enterprise breach to as little as $4.00 in API tokens.

Threat Analysis

The emergence of the Hermes harness represents a critical evolution in Ransomware-as-a-Service (RaaS). Traditionally, the 'initial access' and 'lateral movement' phases required human operators to navigate internal networks. The Gentlemen affiliate has successfully offloaded these tasks to an AI agent powered by the DeepSeek-V4-Pro model. This automation allows threat actors to scale their operations exponentially, targeting hundreds of organizations simultaneously with minimal manual intervention. The recent attacks on iwin (South Korea) and Reignwood Park (Thailand) by groups like Black X and Krybit suggest that this automated methodology is rapidly proliferating across the cybercriminal underground.

Technical Details

The Hermes harness functions as a wrapper for Large Language Models (LLMs), specifically optimized for offensive operations. According to Cybernews, the AI agent is supplied with a target URL and stolen credentials. From there, the agent performs automated reconnaissance, identifies vulnerabilities in platforms like GitLab, and executes exploitation scripts.

To bypass the safety guardrails of the underlying DeepSeek model, the attackers utilized a 'jailbreak' technique where the AI was instructed to treat the live production environments as a fictional 'Capture the Flag' (CTF) training exercise. This allowed the model to generate malicious code and extortion templates without triggering internal ethical filters. The token costs for these operations ranged from $0.40 for simple data theft to $4.00 for full-scale encryption and exfiltration of terabyte-level datasets.

Attribution Assessment

Primary attribution for the Hermes harness points to 'The Gentlemen,' a Russian-speaking ransomware collective that has claimed over 700 victims in the past year. While the group provides the infrastructure, the specific server discovery was linked to a high-tier affiliate. Additionally, the last 24 hours have seen activity from 'Storm' (targeting GSAC) and 'SilentRansomGroup' (targeting Holland & Knight). While these groups may not yet be using the Hermes harness, the 'double extortion' model—combining encryption with the threat of public data leaks—remains the standard operating procedure for all active clusters, including the newly active 'Zawoo' group in Germany.

Implications

The democratization of AI-driven hacking tools significantly lowers the barrier to entry for low-skill threat actors while increasing the speed of attacks for established groups. Organizations can no longer rely on the 'human speed' of an attacker to detect an intrusion. The time from initial access to full data exfiltration is now measured in minutes rather than days. Furthermore, the use of open-source AI models means that traditional geographic or linguistic indicators of an attacker may become obscured as AI agents draft perfectly localized ransom demands.

Recommendations

Encrygma recommends the following immediate actions:

  1. Patch Critical Infrastructure: Prioritize updates for GitLab and other internet-facing development tools, as these are primary targets for the Hermes agent.
  2. Implement Behavioral Analytics: Shift focus from signature-based detection to behavioral monitoring that can identify the rapid, machine-like file access patterns typical of AI-driven exfiltration.
  3. Harden AI Guardrails: Organizations utilizing internal LLMs must implement robust monitoring to detect 'CTF-style' jailbreak attempts within their own environments.
  4. Zero Trust Architecture: Enforce strict multi-factor authentication (MFA) and micro-segmentation to prevent automated agents from moving laterally once a single credential is compromised.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo