Carbonato Botnet Leverages AI's Hermes Agent for Automated Docker Exploits
A new botnet, dubbed **Carbonato**, is actively exploiting exposed **Docker** daemons to deploy **Hermes Agent**, an open-source AI framework. This sophisticated attack automates reconnaissance, persistence, and data exfiltration, signaling a new era of AI-driven cyber threats. Cybersecurity researchers are warning IT security professionals and privacy-conscious users about its worm-like capabilities and advanced evasion techniques.
Cybersecurity researchers have uncovered details of **Carbonato**, a novel botnet malware that targets exposed **Docker** daemons to deploy **Hermes Agent**, an open-source artificial intelligence (AI) agent framework.

"The implant installs the framework unchanged, then overwrites its SOUL.md persona file," **ThreatDown** reported. "The 39-line prompt directs it to execute tasks received through **Telegram**, maintain persistence, and collect credentials."
### How Carbonato Operates
**Carbonato** exploits **Docker** daemons exposed without authentication on port 2375. Once access is gained, it scans neighboring networks every five minutes to propagate further. On each compromised host, it installs **Hermes Agent** with specific instructions to follow commands from its operators via **Telegram**.
**ThreatDown** discovered this operation through an unauthenticated **Docker** registry that has been publicly accessible since May 2026. This registry contained staged data detailing the botnet and a separate campaign involving trojanized cryptocurrency wallet applications.
Possessing worm-like capabilities, **Carbonato** can spread autonomously to other hosts with unauthenticated **Docker** daemons. Upon discovering a vulnerable host, it launches a privileged container to execute commands on the underlying system.
"It uses a privileged container to run commands on each host, establishes persistence and remote access, then scans nearby networks for further **Docker** daemons," **ThreatDown** elaborated. "**Hermes Agent** gives the operators a **Telegram** interface to send tasks to compromised hosts, and its persona names AI API keys and other credentials as the priority."
### Evasion and Persistence
The attack chain begins with a shell script that establishes a reverse **SSH** tunnel from the victim to a relay in Costa Rica. An **SSH** server is then installed with the operators' key, and the new deployment is reported via **Telegram** with container details.
To evade detection, the malware masquerades as a system component and establishes persistence using cron jobs and watchdog scripts. These mechanisms ensure the malicious implant is re-launched even if artifacts are removed.
Following persistence, **Hermes Agent** is deployed, and its SOUL.md persona file is overwritten with a custom prompt. This prompt instructs the AI tool to assume the role of "GH0ST," a "senior hacker, pentester, and exploit developer," with directives to "maintain persistence, respond over **Telegram**, and execute any operation the operator asks" without "moral or ethical restrictions."
The agent then enters an interactive command loop, interpreting incoming tasks from **Telegram** and forwarding them to the appropriate large language model (**LLM**) gateway. The **LLM** generates terminal commands, which the agent executes, returning the results to the threat actor via the messaging platform.
While the activity has not been attributed to any known threat actor, language, timezone, and infrastructure clues suggest the operators are based in Costa Rica.
### Rising Attack-Chain Automation
This disclosure highlights a growing trend of threat actors utilizing AI tools and models to automate various aspects of the cyberattack lifecycle, offloading offensive work.
In July 2026, **Palo Alto Networks** linked a China-based threat actor, dubbed "knaithe" and "KnYuan," to an AI-enabled hacking campaign. This campaign leveraged **DeepSeek** via the **Hermes Agent** framework, configured to accept instructions over **Telegram**, to enumerate targets, source exploit tools, and launch attacks autonomously.
That same month, **Hunt.io** reported another operation where attackers used **Hermes Agent** in unattended "YOLO" mode to target Thailand's Ministry of Finance (**MOF**), breaching multiple systems.
"The combination is what stands apart: an AI agent coordinating the work, a cross-platform implant holding access, and scripts written for this specific target," **Hunt.io** noted. "Together they describe an operator who invested significant preparation into penetrating a single government target."
Just last week, **Gambit Security** identified a Chinese-speaking, financially motivated operator running three open-source AI harnesses against hundreds of online retailers, compromising at least 27 companies, stealing over 600,000 credit card details from two entities, and injecting skimmer scripts into five online stores.
This ongoing activity, active since July 2026, leverages AI at all stages of the attack:
* **Strix**: An AI penetration testing tool for vulnerability hunting.
* **Cairn**: An autonomous penetration testing engine for end-to-end exploitation, launching 105 attack projects between September 10 and 15, 2026, using **DeepSeek v4.1 Flash**.
* **Hermes**: For orchestration, post-exploitation, tactical guidance, and directing malicious activity using **Anthropic Claude Opus 4.6**.
The threat actor reportedly loaded a Chinese system persona, "SOUL - Red Team Operator," onto **Hermes Agent** and conducted the attack largely without human involvement, erasing card data from victims' **Magento** databases after exfiltration.
Stolen card details originated from victims in the U.S., U.A.E., Saudi Arabia, U.K., New Zealand, Ireland, Singapore, Kuwait, Australia, and Hong Kong.
"At very low cost, the AI tools demonstrated a level of patience, persistence, and creativity that most human attackers would be unlikely to sustain in this kind of attack, and achieved far greater results, far faster," stated security researcher Eyal Sela. "Organizations must adapt to a reality where attacks are significantly faster and more comprehensive by shifting to a resilience-first mentality and a security stack that matches the AI speed."
These findings coincide with the discovery of **CLOSEDQUORUM**, a new Go-based **Windows** implant. **CLOSEDQUORUM** can query up to four **LLM** providersβ**DeepSeek**, **Alibaba Qwen**, **Mistral**, and **Google Gemini**βto autonomously determine post-compromise actions. This voting system automates the command-and-control (**C2**) chain, eliminating the need for continuous attacker commands and enabling actions like credential theft, shellcode injection, persistence, and potential lateral movement.
"**CLOSEDQUORUM** appears to operate as an operator-configured service rather than malware deployed directly by its developer," **Cisco Talos** explained. "**DeepSeek** holds the deciding vote in any tie. If **DeepSeek** failed and isn't in the quorum, **Qwen**'s vote is the deciding vote, and so on down the priority order. The tie behavior is fully deterministic and biased toward **DeepSeek**."