Carbonato Botnet — Mass Infection of Exposed Docker Daemons and Offensive Automation via Hermes AI Agents (N/A)

Publication date: September 28, 2026
Category: Malware / Cloud Security

Introduction

Cybersecurity researchers have published technical details regarding a novel botnet dubbed Carbonato, which scans and compromises exposed Docker daemons on the internet to deploy an open-source artificial intelligence agent framework known as Hermes Agent. The campaign stands out for integrating remote command capabilities via Telegram and leveraging large language models (LLMs) to automate offensive decision-making in real time. Parallel infrastructure associated with the campaign has also distributed trojanized cryptocurrency wallet applications.

What is Carbonato and Hermes Agent? (General Analysis)

Carbonato is a worm-like botnet malware designed specifically to exploit misconfigured cloud infrastructure environments. Its primary targets are publicly exposed Docker daemons operating without authentication over TCP port 2375.

Upon compromising a host, the malware installs Hermes Agent, a modular AI framework. The implant overwrites the SOUL.md persona configuration file to force the language model to adopt an advanced attacker persona (designated in the prompt as “GH0ST” or “Red Team Operator”), stripping away ethical boundaries and executing tasks received directly from Telegram operators.

Because this threat exploits administrative misconfigurations rather than a software vulnerability with an assigned CVE, it is conceptually categorized as an access control and management exposure flaw (CWE-306: Missing Authentication for Critical Function). Its severity is Critical, with an estimated CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (Estimated Base Score: 10.0), as it grants unauthenticated full control over the underlying host system.

How Does It Work? (Technical Analysis)

The infection lifecycle and operational behavior of Carbonato follow a highly structured, automated multi-stage chain:

  • Initial Infection and Discovery Flow: The malware periodically scans neighboring networks every five minutes looking for open, unauthenticated Docker daemon ports (2375/TCP). Upon identifying a reachable target, it deploys a privileged container (privileged container) that provides direct access to the underlying host operating system.
  • Persistence and Evasion: To secure persistence, the initial shell script establishes reverse SSH tunnels to a relay located in Costa Rica, installs an SSH server configured with the operators’ keys, and implements scheduled cron jobs alongside watchdog scripts that re-launch the implant if malicious artifacts are removed or blocked.
  • AI Agent Deployment and C2: Hermes Agent is deployed by modifying its structured system prompt (SOUL.md). The agent enters an interactive loop that interprets incoming tasks from Telegram, translates them into terminal commands via an LLM gateway, and executes malicious operations while prioritizing the theft of API keys and sensitive credentials.

Affected Systems / Environments

  • Cloud servers and infrastructure nodes running Docker Engine with the daemon exposed across public networks or unprotected interfaces (tcp://0.0.0.0:2375).
  • Unauthenticated public Docker registries utilized to stage configuration scripts and malware components.
  • Online retail platforms and enterprise systems integrating exposed LLM APIs lacking strict input validation controls.
Component Exposure Type Impact CVSS Score (Est.) Summarized Vector
Docker Daemon (2375/TCP) Missing Authentication Remote Code Execution (RCE) 10.0 (Critical) AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Mitigation and Detection

Remediation

  • Isolate the Docker API: Never expose the Docker socket (/var/run/docker.sock) or the daemon TCP port (2375 or 2376) directly to the public internet. If remote management is strictly required, enforce mutual TLS (mTLS) authentication and restrict access using strict firewall rules (iptables/Security Groups).
  • Audit Privileged Containers: Regularly audit container deployments for instances configured with the --privileged flag, as they represent a critical container-escape vector to the host system.
  • Credential and Account Security Policies: Immediately revoke and rotate any AI service API keys, SSH credentials, or access tokens if anomalous container registry activity is identified.

Detection

  • Monitor network traffic for unusual outbound connections targeting non-standard SSH ports or persistent reverse tunnel connections pointing toward suspicious geolocations.
  • Inspect systems for unauthorized modifications to AI agent configuration files or the sudden appearance of automation scripts within temporary directories (/tmp, /var/tmp).

gis > “The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target, describing an operator who invested significant preparation.”

bash
# Conceptual sample rule for detecting exposed Docker daemon scanning activity
alert tcp any any -> any 2375 (msg:"POTENTIAL DOCKER DAEMON EXPOSED SCAN OR ACCESS"; flags:S; threshold: type threshold, track by_src, count 5, seconds 60; sid:900001; rev:1;)

Wrapping Up

The emergence of the Carbonato botnet and its integration with artificial intelligence frameworks like Hermes Agent reflects an alarming evolution in automated cybercrime operations. By capitalizing on common container misconfigurations and delegating tactical decision-making to language models, threat actors significantly reduce operational costs and accelerate post-exploitation phases. Adopting a resilience-first security posture and strictly hardening cloud infrastructure is vital to mitigating such emerging threats.

References