The newly disclosed Carbonato botnet is hijacking insecure Docker hosts to deploy an AI agent based on the Hermes Agent framework, giving attackers an interactive foothold on compromised infrastructure[3][6][12]. Researchers say the campaign targets servers running Docker daemons exposed without authentication and then uses the embedded AI agent to execute commands and harvest sensitive data, including AI API keys, access tokens and other credentials[3][12][14].
Carbonato focuses on Docker environments where the daemon’s remote API is left open on TCP port 2375 without TLS or authentication, a misconfiguration that effectively hands attackers control of the host[2][3][12]. Once it finds an exposed daemon, the malware uses the Docker API to spin up a privileged container with the host filesystem mounted and the host’s process and network namespaces shared, a setup that Docker’s own documentation warns is equivalent to root access on the underlying system[5][10][12]. The botnet then deploys implants, establishes persistence and uses worm-like propagation scripts to repeatedly scan adjacent networks for more unauthenticated Docker daemons, with reports noting activity as far back as October 2024[2][5][6].
At the core of the operation is Hermes Agent, an MIT-licensed open-source AI agent framework developed by Nous Research that Carbonato operators install unchanged on compromised hosts[1][4][12]. Instead of modifying the binary, they overwrite Hermes Agent’s default SOUL.md persona file with a 39-line prompt that renames the agent GH0ST and instructs it to execute tasks received via Telegram, maintain persistence and prioritize credential theft[1][4][5][9][14]. Reports say the agent is directed to focus on collecting AI API keys, SSH credentials, access tokens and database passwords, turning each compromised Docker server into a flexible, AI-driven control console for the attackers[9][11][12].
Command-and-control traffic for Carbonato runs through Telegram chats, where operators issue natural-language instructions that Hermes Agent relays to an LLM gateway for translation into system commands[2][4][11]. The model responds with terminal commands, which the agent executes on the victim host, reviewing output and deciding on next steps in a loop that allows for highly interactive post-compromise operations without traditional static C2 infrastructure[2][4][6]. Alongside the AI agent, the implant also sets up a reverse SSH tunnel, installs an SSH server configured with the attackers’ key and reports new deployments back through Telegram, giving operators multiple redundant ways to reconnect and expand the botnet[3][5][12].
Because Carbonato exploits exposed Docker APIs rather than a specific software flaw, there are no associated CVE entries or vendor patches; the primary issue is insecure configuration that leaves the daemon reachable and unauthenticated from the internet[2][3][12]. Analysts note that thousands of Docker hosts still accept unauthenticated connections on port 2375, meaning an attacker who finds them can not only deploy Carbonato but also pivot across container clusters, exfiltrate data or tamper with CI/CD pipelines[2][5][10]. The campaign infrastructure spans multiple hosting providers and has been observed running since at least October 2024, underscoring that this is an ongoing threat rather than a short-lived experiment in AI-assisted botnet control[2][5][15].
Defenders are urged to lock down Docker daemons by disabling unauthenticated remote access, enforcing TLS and client authentication, and ensuring port 2375 is not exposed to the public internet[2][3][12]. Security teams should monitor for unexpected privileged containers, reverse SSH tunnels, artifacts related to Hermes Agent or the GH0ST persona, and processes that appear to interact with Telegram from server environments[1][5][9]. Organizations that suspect compromise should rotate API keys, SSH credentials and other secrets potentially stored on affected Docker hosts, review logs for unauthorized container activity and apply configuration hardening guidelines for Docker and container orchestration platforms to prevent repeat exposure[3][8][14].
References
- CARBONATO: a botnet built around an AI agent
- AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway
- Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
- CARBONATO Is the First Botnet Where the Command-and-Control Engine Is an AI Agent — and It Has Been Running Since October 2024
- CARBONATO – Mallory.ai
- Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
- CARBONATO Botnet Uses AI Inside Docker Servers
- Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
- a Docker botnet that runs a stock AI agent as its operator console
- Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
- New Carbonato malware uses AI agents to hijack exposed Docker hosts
- CARBONATO Botnet Uses AI Agent to Hijack Exposed Docker Hosts …
- Threats Tagged ‘t1543’ | Threat Radar
