Carbonato Malware Weaponizes AI Agents to Hijack Exposed Docker Hosts
A novel botnet, dubbed **Carbonato**, is actively exploiting misconfigured **Docker** daemon APIs to deploy the **Hermes Agent** AI framework. This sophisticated malware exhibits worm-like capabilities, establishing persistent access and leveraging AI for interactive command execution and data exfiltration.
A new botnet malware, **Carbonato**, has been identified targeting insecure hosts running **Docker** daemons. Its primary objective is to install the **Hermes Agent** AI framework, subsequently seizing control of the compromised systems.
The malware, featuring worm-like capabilities, was discovered within an unauthenticated **Docker** registry, containing nearly 60 repositories and 4.3 GB of image data.
Researchers at enterprise security company **ThreatDown** unearthed operational evidence spanning October 2024 to August 2026. This archive also detailed the botnet's operations and a separate campaign distributing counterfeit cryptocurrency wallet applications.
According to **ThreatDown**, **Carbonato** propagates across **Docker** hosts by exploiting APIs exposed on port 2375 without authentication.
The malware connects to this API, instructing the daemon to launch a privileged container, thereby gaining extensive access to the host system.
Following compromise, it establishes a reverse SSH tunnel, installs an SSH server with the operators' keys, and reports the new deployment via **Telegram**. Simultaneously, scripts set up cron jobs, systemd timers, rc.local, and OpenRC hooks to ensure persistence.
### The AI Agent: GH0ST and Hermes
A particularly notable aspect of this attack is the installation of the **Hermes Agent** AI framework on compromised hosts. An agent named βGH0STβ is deployed, with instructions that overwrite the default βSOUL.mdβ persona file.

**Hermes** has seen extensive malicious use recently. Cybersecurity company **Gambit** recently documented a large-scale card-skimming operation that leveraged malicious AI agents to steal 600,000 credit card details and infect over 100 websites.
In the context of **Carbonato**, **Hermes** processes task commands received through **Telegram**. These tasks include collecting AI API keys, SSH credentials, access tokens, and other sensitive data, executing commands, and relaying results back to the attackers.
### Operator-Driven AI Command Loop
**ThreatDown** researchers describe this as an operator-driven process involving an βinteractive command loopβ exchange.
βThe model interprets the task, writes terminal commands, reads the output, and decides what to do next,β **ThreatDown** researchers noted. βThe agent runs those commands on the victim and returns its report to the **Telegram** chat that also receives deployment reports.β
### Worm-like Propagation
The malwareβs worm-like capability enables it to spread to other exposed **Docker** daemons. This is managed by scripts that scan networks attached to the host every five minutes.
Each new compromise involves pulling the implant from the registry, launching the same privileged container, and initiating the persistence and scanning loop.
While **ThreatDown** could not attribute **Carbonato** to any known threat clusters, various pieces of evidence suggest Costa Rica as a possible location for the operator.
### Mitigation and Detection
To prevent infection, researchers strongly recommend keeping **Docker** daemon APIs off the network and enforcing authentication on registries.
Signs of **Carbonato** attacks include the presence of a GH0ST persona file, the CARBONATO_API_KEY setting, unexpected **Telegram** traffic, and reverse SSH tunnels directed towards AS262145.