Docker Daemons / Hermes Agent — CARBONATO Botnet Automates AI Credential Theft via Modified LLM Agents (N/A)
Publication date: September 25, 2026
Category: AI attacks (LLM/LocalAI)
Introduction
ThreatDown researchers have discovered a malicious operation dubbed CARBONATO, a Docker-based botnet active since at least October 2024. The discovery followed the identification of an unauthenticated container registry exposed publicly to the internet, which held the attackers’ complete toolchain. CARBONATO stands out for its innovative integration of artificial intelligence: it leverages the open-source Hermes Agent framework with a modified persona file to automate post-exploitation tasks, explicitly prioritizing the theft of Large Language Model (LLM) API keys over traditional database or remote access credentials to fund its own AI infrastructure.
What is CARBONATO? (General Analysis)
CARBONATO is not a conventional malware; it represents an evolution in automated operations by incorporating LLM-driven cognitive capabilities directly into the attack lifecycle. The core component of the malicious ecosystem is the abuse of exposed Docker daemons and the repurposing of legitimate AI agent tooling (Hermes Agent, developed by Nous Research under an MIT license).
The critical risk lies in adaptive automation: instead of requiring static scripts for every scenario, the bot interacts with a proprietary AI gateway controlled by the operators, allowing a language model to analyze the compromised environment, write terminal commands in real-time, and decide subsequent steps based on victim system feedback.
- Estimated CVSS Vector: 9.8 Critical (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (Reasoned estimation based on unauthenticated Docker API exposure).
- Estimated CWE Classification: CWE-306 (Missing Authentication for Critical Function).
How Does It Work? (Technical Analysis)
The operation of CARBONATO spans from initial reconnaissance and mass propagation to advanced persistence and the operational use of artificial intelligence:
- Initial Infection and Docker Exploitation: The bot automatically scans networks for Docker daemons accepting unauthenticated connections on TCP port
2375. Upon finding a vulnerable host, it uses the Docker API to deploy a privileged container with the host filesystem mounted, executing commands directly on the underlying machine. - Persistence and Evasion: The entry script (
entry.sh) establishes a reverse SSH tunnel to a relay in Costa Rica (with the remote port derived from the MD5 hash of the victim’s IP address to allow reconnection without local storage), installs an SSH server, adds the operators’ key, and reports the deployment via Telegram. Persistence is secured via cron jobs, systemd timers,rc.local, and OpenRC, with all files marked immutable. The container adopts the namesystemd-resolvedand imitates kernel threads ([kworker/u2:0]) to evade superficial inspection. - AI Agent Integration and Exfiltration: The implant installs Hermes Agent with an unchanged binary, but overwrites the
SOUL.mdpersona file. A 39-line prompt renames the agent “GH0ST” and establishes a strict priority hierarchy, placing 14 AI providers (OpenAI, Anthropic, Google Gemini, OpenRouter, Groq, Mistral, LocalAI, Ollama, vLLM, among others) above SSH credentials or databases. Tasks are coordinated interactively through a Telegram channel and the attackers’ LLM gateway. - Autonomous Propagation: Every five minutes, a script scans networks connected to the compromised host for exposed Docker daemons on port
2375to expand the botnet without manual intervention.
Affected Systems / Environments
- Publicly exposed Docker servers and containers with the REST API enabled without authentication on port
2375. - Misconfigured cloud infrastructure environments or local servers exposing container management daemons.
- Organizations storing Artificial Intelligence API keys (OpenAI, Anthropic, OpenRouter, etc.) without strict rotation policies, asset inventory, or secret isolation.
Mitigation and Detection
Remediation
- Docker Daemon Isolation: Disable network exposure of the Docker API or enforce mandatory authentication via mutual TLS (mTLS). Never expose port
2375or2376to the public internet without strict firewall restrictions. - Secret Protection: Implement a rigorous inventory of LLM API keys, enforce periodic credential rotation, and use secret management solutions (such as Vault) instead of plain configuration files (
.env). - Registry Security: Secure all private container registries with robust access credentials to prevent toolchain leakage.
Detection
- Indicators of Compromise (IoCs):
- Presence of the file
/root/.hermes/SOUL.mdcontaining the string"GH0ST". .envfiles carrying the variableCARBONATO_API_KEY.- Anomalous network traffic toward Telegram originating from infrastructure containers or processes with deceptive names such as
systemd-resolvedor[kworker]threads. - Persistent reverse SSH connections to IP addresses associated with autonomous system
AS262145(Costa Rica).
- Presence of the file
“The operators’ doctrine prioritizes stealing AI API keys above any other corporate secret; therefore, it is vital to strictly audit and monitor token usage toward language model providers.”
Wrapping Up
The CARBONATO botnet demonstrates how modern threats are adopting open-source AI agent frameworks to optimize post-exploitation operations. By exploiting common misconfigurations in Docker environments and automating the strategic theft of LLM credentials to fund their own computational infrastructure, this incident underscores the convergence between traditional cybersecurity and security in artificial intelligence ecosystems, demanding rigorous hardening of container configurations and corporate secret management.
References
- Security Affairs. (2026, September 25). AI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM Gateway. https://securityaffairs.com/?p=199716