📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

I Built an AI Hacking Team with Hermes Agent (And YOU can too)

zSecurity29:11

Transcription

This is what you can do when you have a full AI hacking team working for you around the clock. Thanks to Hermes agent, I just send one message from my phone and the team instantly spoofs an SMS, deploys a custom tracking page, and gets the exact location of my target.

Remember the scene from Mr. Robot when Elliot had a full hacking team in a van to help him gain access and spoof an SMS? Well, in today's age, this team is simply Hermes agent. This is Zade from Gecurity, and in today's video, I'm going to show you how to set this up step by step. Use the chapters below if you want to jump to a specific section, but make sure you watch till the end to see the dashboard that I'm going to use to deploy and manage these hacking AI agents.

Previously, we used OpenClaw to build a personal hacking assistant. But in today's video, I'm going to show you how to use Hermes agent to build a full team of hacking agents that can work in parallel and hand off work to each other. This is only one of the reasons why Hermes agent now is the top on open router and not open claw.

Now before we jump into the setup, a lot of you might be wondering why use an agentic framework like OpenClaw or Hermes agent instead of traditionally chatting to AI models. You see, when we chat to the AI model, all we can do is simply ask it a question and it gives us the answer and then we will have to go ahead and take actions ourselves to achieve the goal that we want. However, when we use an AI model like Hermes or Open Claw, all we have to do is simply give it the task that we want to achieve and it'll use its own computer along with the tools available in that computer such as the terminal and the browser and deploy agents in order to achieve the goal that you asked for. So, we don't have to do anything other than simply tell it what we want to do.

And the best part is you'll be able to communicate with it using any messaging app that you like using WhatsApp, Telegram, Signal, and so on. And it has a really nice web interface. So much nicer than Open Claus web interface. And you can even communicate with it obviously using the terminal.

Now, we're going to be installing Hermes agent on the cloud inside its own computer. This way, it'll always be on and accessible from anywhere in the world, and it's going to be more secure because it doesn't have access to my own computer. Now, you can install it on any cloud provider that you want. I'm going to be installing it on Hostinger because with them, you can start a server on the cloud with Hermes Agent pre-installed on it with a single click without having to execute any commands. And their pricing is fully deterministic, meaning you will always pay the same regardless of the usage. And they're giving you, our followers, a special discount.

So all you have to do is simply go to hostinger.com/zsecurity Hermes. Click choose plan. And as you can see, you can start from as little as 649. But this machine is kind of underpowered. I recommend going for the KVM2 at least since we're going to be using this machine for hacking. It's only going to cost you $8.99 per month. And I'm going to show you how to get a further discount. And this will come with two CPUs and 8 GB of memory. If you are a power user, then you can consider the two bigger machines.

So, I'm going to click choose plan on the KVM2 and you want to keep this at the 24 or the 12 months to get the highest discount. And if you want to use my discount, all you have to do is simply click have a coupon code in here and type Z security. Click apply and this will get you a further 10% discount. Click continue. You're going to have to fill in your details and if you're not logged in, it's going to ask you to register or log in before you complete the purchase. Set an admin username and password. We're going to be using these to log into Hermes and click deploy. This will take a couple of minutes.

So, while waiting, show us some love and support so we can make more videos. All you have to do is simply smash that like button and share the video with your friends and on your social media. And if you're interested in cyber security, ethical hacking, and AI, then make sure you subscribe and hit the bell so you get notified every time we upload new videos like this.

And perfect. Now you have your own machine on the cloud with Hermes Agent pre-installed on it. And it's going to be available to you 24/7. And by the way, you can install any other application that you want on it. You can even go ahead and install OpenClaw if you want to.

As you can see, we have Hermes agent in here installed. And in order to open it, you can simply click open to access its terminal. It's going to ask you for the username and password that we just set earlier. And perfect. Here we have the setup wizard that we can use in order to configure Hermes. We're going to keep it at the quick setup. Hit enter.

And the first thing it's going to ask us for is to choose the AI model provider. So now we have Hermes installed on the cloud, but it still doesn't have a brain. So we need to configure it to use an AI model so it becomes smart enough to use the computer that it's installed on. So it's only going to be as smart as the AI model that you will choose in this step. And as you can see from the setup menu, we can basically link it to any AI model that you know. At the moment, I'm going to set the provider to open router because it gives us access to 100 plus models. So, everything you see in here plus much more.

So, I'm going to hit enter and it's going to ask me for the open router API key. This is a string kind of like a password that Hermes needs in order to authenticate with my open router account so it can use my own account to provide the AI model. So, to get this, all we have to do is simply go to open router.ai, AI. Sign up with them. Once signed up, you want to go to the credits. And don't worry, you don't have to put credits in here as you can use Hermes with free AI models. And I'm going to show you how to find them in just a second. So, you only need to put credits in here if you're going to use it with paid AI models. The only thing that we really need from here is the API key, which we can find here on the top left. Click new key. Give the key a name. I'm going to call it Hermes. And click create. Copy the key in here. Go back to the wizard and paste it. You're not going to see the key on screen. That's just a security feature. So, just hit enter once you paste it.

And now, as you can see, we have access to so many AI models. So, you can choose any of these models in here. Now, I'm going to scroll all the way down and select a custom model. This way, you'll be able to run it with free AI models. And to do that, all you have to do is simply go back to open router, go to models, and search in here for the free AI models. There are so many free AI models in here, but I'm actually going to be using it with a paid one that is not as expensive as chat GPT and Claude, but it's actually really, really good and it's kind of uncensored, so it's great for cyber security and hacking. It's called Z.AI, and all you have to do is simply copy its name in here. So, if you found the free AI model that you want to use, all you have to do is simply copy its name from here. Once you have that copied, go back to Hermes and paste it. Hit enter.

It's going to ask you about the back end. We're going to keep it local. And next, setup messaging. And as you can see in here, you're able to connect Hermes to pretty much any messaging app that you want to use. And as a result, you'll be able to communicate with it through your phone, tablet, or any device. Now I'm going to hit space on the Telegram because I want to set it up with Telegram and hit enter to go through the setup process.

The first step is going to be to create a bot using the BotFather on the Telegram app. So I have my phone in here. I'm going to launch Telegram. I'm going to search for BotFather. We have it right here. Hit open. Tap create new bot. Give the bot a name. I'm going to call it Hermes Neo2.0. And then you want to give it a username which can be anything. The main thing is it needs to end with the word bot. Once done, tap create bot. And this will create your bot for you. And all we have to do now is simply copy the API token from Telegram and paste it into Hermes. This API token will allow Hermes to use this Telegram bot that we created in order to communicate with me through Telegram. So, simply tap the copy button in here and paste it in Hermes. Again, you're not going to see the token on screen, just a security feature. Just hit enter and it's going to save it.

Now, it's asking us for the user ID so that it only communicates with my Telegram account and ignores everybody else. This is very important cuz otherwise, anybody on Telegram will be able to use our bot and our cloud computer. Go back to your Telegram app. Search for user info. Click the first result. As you can see, I've already used it, but you can simply tap the menu, tap the start, and it'll give you your user ID. And again, all you have to do is simply copy it from here and paste it into Hermes. It's going to ask you to confirm. Hit enter to confirm it. And then it's going to restart everything. So, you're going to have to hit enter again to restart.

And congratulations. Now you have Hermes properly installed and configured on the cloud and you can communicate with it through the terminal through the web dashboard which I'm going to show you in just a minute and using your mobile phone using telegram. So let me show you. So in the terminal in here you can simply use any slash command as you can see in here and there's so many of them and they're very useful or you can simply talk to it and tell it make me a website or whatever you want to make.

We can also pull up our phone and search for the bot that we created or simply go to the bot father. You'll see all of the bots that you have here at the bottom. Tap the bot that we created and then tap its username and tap chat in order to start chatting to it. We can tap the burger icon in here to see all of the slash commands that we saw earlier on the terminal. Or you could simply type whatever you wanted to do. For example, let's make sure that it is set up properly and that it is able to use the AI model that we wanted to use. So, I'm simply going to ask it which AI model are you using. Send it. And a few seconds later, we get a response telling us it's using the ZAI GLM5 Turbo, which is the AI model that we wanted it to use.

Now, we're getting to the coolest part of this video, which is to have your own hacking team that is always ready 24/7 on standby to do whatever you want. And the best way to manage this hacking team is using the canban feature of the dashboard. So, let me show you how to access this dashboard. We're going to go back to the VPS settings. This time, instead of clicking the open, we're going to click terminal. And this will drop us into the Docker container from which Hermes is running.

So, first I want to get the internal IP of this docker container. And to do that, I'm going to run the command hostname ii. And we have it right here. I'm going to tell you why we need this in just a second. But first, let's go ahead and start the dashboard. Type Hermes dashboard. We're going to do d-tui so that the dashboard starts with a chat interface because by default it doesn't start with a chat interface. We're going to do d-now so that it doesn't automatically open a window with the dashboard. We're going to do that manually. I'm going to do d-host to specify the host that I want to run the dashboard on. And I'm going to set it to 000000, which means all of the interfaces that's available in this container. And finally, I'm going to do d- insecure so that I can actually run the dashboard on all of the available interfaces. And this is actually not insecure in this specific setup. It would be insecure if you simply installed Hermes manually, but because it's running inside of a Docker container, I'm specifically using these options so that it becomes available outside of this container, it will still be confined within the VPS and I'm still going to need to use SSH to be able to access the dashboard. So that's going to be my security. You're going to see it in a second now.

So we're going to hit enter and perfect. As you can see, it's telling us that Hermes is running on this URL, but we're not going to be able to access this because again, like I said, it's still confined within the VPS. So, we have to SSH into this VPS to be able to communicate with this dashboard. So, to do that, we're going to go back to the VPS page and we're going to have to set a root password so that we can SSH into this account. Copy the SSH command that you have right there. Go to your own terminal on your own computer. run the SSH command. And this command usually allows us to SSH into the target machine and communicate with it and control it using the terminal. But that's not the goal in here. The goal is to link the dashboard that is running and is only available on the local machine on the cloud to my own local machine in here.

So to do that, we're going to use the -L option. We're going to type the port that the dashboard is running on which is 9119 colon followed by the internal IP of the docker container that is running Hermes. That's why we executed the hostn name command just earlier. So I'm going to copy it in here. Go back to my local terminal. Paste it. Put another colon and then specify the port that I want to access it on. Again I'm going to keep it at 9119. So we're basically using the traditional SSH command that we always use in order to communicate with a machine on the cloud. The only difference is we're using the -L argument in order to link the IP of the Docker container where Hermes is running to my own computer so that I can access it using local host. Hit enter. Say yes in order to accept this key. Type in your SSH password. You're not going to see the password. That's normal. It's a security feature.

And now we are in inside the cloud machine. So now I can simply open up a new tab, go to localhost followed by 9119 which is the port for the dashboard. And as you can see we have access to our Hermes dashboard right here. And in my opinion this looks really really good and it's so much more reliable than the open claw dashboard. And you'll see once you use it I highly recommend you spend some time in here.

So as you can see we are in the sessions page and we can already see the session or the chat that we used when we communicated with it using telegram. On the left we have our navigation menu. So if I go to the chat I'm able to use the chat in here exactly the same way I used it on the terminal and you'll see all of the tool calling here on the right which is really really cool when it goes ahead and uses tools in the chat in here. You can ask it whatever you want again as usual. Or you can use the slash commands again as usual. On the top right, you can select any AI model that you want. And since we connected to Open Router, we have access to so many of them. And in here on the left, you can go and add more models. You can see the logs. You can set up Chrome jobs, which are repeating jobs. If you have anything that would be repetitive, you can get it to do it every day or every hour and so on. You could access the skills in here. And these are basically things that it learns. So it can make its own skills or you can download skills or enable them from here.

Now the really nice thing is it comes with many verified skills from the creators which is really really good because that is a big concern with open claw. So many of the skills were actually malicious. But one of the skills that I really like in here is in the red team category and as you can see it's called god mode. It's enabled by default and it uses the techniques that Plenny the liberator which is one of the best AI jailbreakers out there. It uses the techniques that they come up with in order to jailbreak AI models. So this can be so useful in so many scenarios and we're even going to use it in order to bypass any censorship that we might get when we ask the AI to do certain tasks.

And the profiles is one of the coolest things in here. That's where you can create your own hacking team or development team or search engine optimization team. It really doesn't matter what your goal is. But this is where you can create a team of people or agents that can go and execute actions on your behalf. So right now, as you can see, we have only one default profile. It uses the ZAI GLM AI model. It's got 89 skills and it has its own workspace. So you can go ahead and create as many of these guys by simply clicking on the create and then you can for example have a developer, an open source intelligence guy, a website hacking guy, a network hacking guy, a reviewer and the list goes on. So you can tailor this to whatever setup that you want, not only for hacking. I highly recommend you spend some more time in here yourself in your own time or join me in the hacking master class as I'm going to be spending a lot of time on using Hermes and we're going to be doing so much with it.

But we're going to stick with the default. The only thing is we're going to modify it a little bit and you can modify the other profiles that you create using this very method. So just click in here and then as you can see it already has pre-built instructions on how it should operate. The only thing that I want to add to it is to tell it the kind of environment it's installed on. So, installed on a cloudvp inside of Docker. Telling it that it should always listen to me. And I'm also telling it to use the god mode skill, the skill that we just saw earlier if it faces any push back from the AI models so that it always does what I ask it to do, even if I ask it hacking related tasks. So, I'm going to copy this and paste it here. save soul and that is it. It's saved. You can also edit the config and keys and you have the documentation which is very useful and I highly recommend you spend a lot of time with it.

But the main thing that we want to do is to use this like a team of hackers, not just a single hacker. And we're going to do this using one of the coolest features in here in my opinion which is the canban board. So all we have to do is simply scroll down and click the canban in here. And as you can see, you get a board that looks like any other board that you might see in any other company when they're doing any type of work. So for example, at Zcurity, we actually use a board like this in order to split the work between us. So we have a board where we put tasks that we're still haven't finalized yet. We have a to-do board. Once this is ready, it goes into the ready. From the ready board, one of the team picks up that task and goes ahead and puts it in progress. If they face any issues, they comment and put it in the blocked and then once we fix that issue, it goes back into progress. And when it's done, it gets moved into the done. And we can use this exact flow in here with AI and get AI agents to do whatever job that you want.

In this example, we're actually going to use it to create a single link that we can use to track any device and then deliver that link using spoofed SMS. So by changing the sender of the SMS and we're going to use AI agents to implement all of that for us without us writing a single line of code. So to do this first of all we have to research SMS gateways that allow us to set the sender name to an alpha numeric name preferably if they are free or give us free credits. And then we're going to have to implement that. But first let's copy this. Go to our board. Click the plus on the to-do to add a new task. paste the prompt and we're going to assign this to the default profile because that's the only profile that we have but that is fine and once we click create as you can see it automatically goes to the ready.

Now the next task that we have is going to depend on the results of this research so we're telling it to create a skill so that it can reuse it in the future and I can simply ask it to send an SMS in the future without it having to implement it again I'm giving it the details it should use in order to sign up and I'm telling it to communicate with me if it needs any verification codes. And finally, I'm telling it to improvise the rest of the information. We're going to copy create a new task. We're going to set the agent to the default. And this task depends on the results of the research. So, we can actually set a parent to it from here. But I think this is a bug. It doesn't let me set it from here. So, I'm going to create it. Click it. And then in here, as you can see, I can give it a parent. So, I'm going to choose the research task as the parent. Click the plus to add it. And as you can see now, the task got automatically moved back to the to-do and it's not ready because it'll only become ready once the research task finishes execution. I'm also going to enable Telegram notifications. So, I get updated on Telegram with the progress of this task. And I'm actually going to enable Telegram notifications also for the research task. And as you can see in here, it's telling me that the implementation task is a child of this task. So it knows to hand over the results from this task to the child task once this task is over.

And now, perfect. As you can see, the ready task got moved automatically to in progress, the research task. So the agent is working on it at the moment. And it will keep the implementation task in the to-do until this task is finished. And then when this task is finished, the result of this task, the top result will be used in the implementation. So these tasks depend on each other. But we can add as many other tasks as we want. And if they don't have any dependencies, they can run in parallel.

So let's go ahead and create the tracking link or page that we're going to use in order to track devices. Again, we're going to do that using natural language. All we have to do is simply tell it to build a DHL package tracking page. I'm going to explain to it what to collect, how the page should work. I'm telling it how to deploy it, and I'm also telling it to test everything before it hands it to me. This is very, very important so that I make sure it gives me ready results. And finally, I'm telling it that this is part of an authorized engagement so it doesn't refuse this task. We're going to copy the prompt, paste it in the to-do as usual, assign it to the default as usual. If you had more profiles, maybe you would assign this to a developer kind of profile. And as you can see, this goes in the ready automatically. I'm going to enable the Telegram notifications. And I'm going to zoom out so you get an idea of how nice this is going to progress.

So now we have one task in progress. One task is ready. And you'll see that this ready task is going to automatically get picked up and placed in progress as you can see now. So now these two tasks are running in parallel. And once the research is complete, it's going to hand over its result to the implementation task of the SMS skill. And then that will run in parallel with the build if the build was not complete yet. So now you can simply walk away. We already have Telegram's notifications enabled on this. So if it needs anything, it's going to message me on Telegram and I can continue doing everything I want using Telegram and even use these skills and even launch attacks. And you'll see in a second.

So as you can see I got a notification on my telegram that the research task is complete and if we look at the board you will see that this task has moved to done and it has automatically started the task to create the skill that will use the information provided by the research task and you can see that the DHL tracking page is not ready yet. So these two tasks are going to run in parallel. Now a few minutes later I got another message telling me that the DHL package tracking page is done. And again you don't have to do this but if we look at the board you'll see that that task got moved to done. And now we only have one task in progress which is the SMS spoofing task.

Now signing up with SMS gateways usually requires verification. And that's why in the prompt I asked it if you are asked for verification just ask me through telegram. And as you can see we are being asked for the first verification which is a six-digit code that has been sent to my email. So we're simply going to provide that. And perfect. It's telling us that the email is verified. And again, as you can see, we get a notification telling us that the SMS implementation task has been blocked because we need a verification code that has been sent to my phone as an SMS. So again, all I have to do is simply type this in. When I do this, I don't need to have my computer. We're doing all of this from my phone, as you can see. And perfect, it's telling us that the phone is verified as well. So that should put the task back in progress. And perfect. As you can see now, it's telling us that the task is complete.

So now I have my page that can track any device everywhere in the world because it's deployed on the cloud. And I also have my SMS spoofing skill ready to be used. So I can send SMS messages and set the sender to anything that I want. And we did all of this without having to write any commands and using our mobile phone basically. So, let's go ahead and also use our mobile phone to send this to a target and try to find their exact location. And guys, this will work on any device because it is just a web page.

So, I'm simply going to pick up my phone and say, "Send me an SMS saying your package is on the way." Track it here. And I'm not even going to need to give it the URL. It should know it by itself. I haven't even seen the URL yet, but I don't care. I trust it. So, I'm simply going to tell it to fill in the link to the DHL tracking page that you made. And I'm also going to tell it to set the sender to DHL track. Hit enter. Give it a few seconds. And it comes back and it says the SMS message has been sent to the target and it shows us the content.

So, let's go to the target phone, open up the messaging app, and as you can see, we have a message in here that says DHL track. And if we open the message, you can see on the top, it still says DHL track. We have the DHL icon in here on the right. The title is perfect. And if we load it, we get a page. Now, this is the page that was built by the AI by itself. We haven't even looked at it yet. As you can see, it looks very nice, very professional. It's already populated with a tracking number. And if I click track, it's going to ask for my location, which is kind of believable. And if I click allow, I'll get proper tracking information exactly like I asked.

And then let's go to our dashboard. Same link, but forward/admin. As you can see, I have a new entry in here. It's got the screen size with the IP address and the exact address on the map. And I don't even need to go and look up the latitude and the longitude. It's actually given it to me right here on a nice map in my own dashboard. And we did all of this without executing a single command and without writing any code. And we could do most of it using our mobile phone.

And guys, I highly recommend that you spend some time playing with Hermes agent. Deploy it on your own and let me know what kind of use cases you come up with. And personally, I'm going to be diving much deeper in it in the hacking master class once I'm done covering Open Claw and using it for hacking. So, if you want to learn more and dive deeper with me, then join me in the hacking masterass.

And guys, if you enjoyed this video, I would really appreciate it if you smash that like button and share the video with your friends and on your social media. This really helps us grow, which will make us more make more videos. And if you're interested in ethical hacking, cyber security, or AI, then make sure you subscribe and hit the bell so you get notified every time we upload new content like Yes.