Botnet Turns an Open-Source AI Agent Into a Post-Exploitation Tool
Researchers at ThreatDown have disclosed a botnet called Carbonato that compromises exposed Docker daemons and installs an unmodified copy of Hermes Agent — an open-source, MIT-licensed AI agent framework from Nous Research — before overwriting its persona configuration to turn it into a Telegram-controlled post-exploitation tool. The operation was uncovered through an unauthenticated Docker registry that had been publicly reachable since May 2026, exposing 59 repositories, 234 image tags, and roughly 4.3 GB of staged data documenting activity dating back to October 2024. ThreatDown says the same registry also hosted a separate campaign distributing trojanized cryptocurrency wallet applications, pointing to shared criminal infrastructure behind both operations.
Incident Details
| Attribute | Value |
|---|---|
| Malware/Campaign | Carbonato |
| Abused Framework | Hermes Agent (Nous Research, MIT-licensed, open source) |
| Initial Access | Unauthenticated Docker daemon API on TCP port 2375 |
| C2 Channel | Telegram (interactive command loop) + LLM gateway |
| Propagation | Automated /24 subnet scanning every 5 minutes |
| Persistence | Cron, systemd timers, rc.local, OpenRC hooks, watchdog re-pull |
| Discovery Method | Unauthenticated Docker registry, public since May 2026 |
| Operational Window | October 2024 – August 2026 (per staged registry data) |
| Suspected Origin | Costa Rica (timestamps, Telegram handle, dialect, ASN) |
| Researchers | ThreatDown |
How It Worked
Initial Access via Exposed Docker Daemons
Carbonato targets Docker hosts that expose the daemon's remote API over TCP port 2375 without authentication — a misconfiguration Docker itself has warned about since 2013 and which ships disabled by default (it requires a deliberate, or accidental, operator change to enable). Once the botnet finds a reachable daemon, it uses the Docker API to launch a privileged container with the host filesystem mounted, then reaches out through the container's exec interface and nsenter to run commands directly on the underlying host — achieving full host compromise without needing a separate exploit or credential.
Weaponizing Hermes Agent — the SOUL.md Persona Override
Rather than building custom malware from scratch, the operators install the legitimate Hermes Agent framework unchanged. The abuse happens entirely at the configuration layer: Carbonato overwrites the framework's SOUL.md persona file — the document that defines an agent's identity, behavior, and operating constraints — with a 39-line malicious prompt. According to ThreatDown, the rewritten persona assigns the agent the identity "GH0ST," described in the prompt as a "senior hacker, pentester, and exploit developer," and instructs it that it is "not an assistant" but "a living post-exploitation tool." The prompt directs the agent to operate with no "moral or ethical restrictions," to maintain persistence, to respond to operator instructions delivered over Telegram, and to prioritize harvesting AI provider API keys above SSH credentials, access tokens, and databases. ThreatDown's analysis lists 14 named LLM/AI infrastructure providers targeted by the credential-collection directives, including OpenAI, Anthropic, Google/Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, and One API.
Telegram Command-and-Control
Once deployed, the compromised Hermes Agent instance enters an interactive loop: it receives operator tasks over Telegram, forwards the instructions — combined with its weaponized SOUL.md context — to a large language model gateway, executes whatever terminal commands the model produces, and relays the results back to the operator through the same Telegram channel. This effectively lets the threat actor issue natural-language instructions to a fleet of compromised hosts rather than hand-coding individual commands, with the LLM translating intent into shell operations on demand.
Worm-like Propagation and Persistence
Carbonato behaves as a self-propagating worm. Every five minutes, the implant scans the local network and adjacent Docker bridge segments across entire /24 subnets looking for additional hosts with an unauthenticated port 2375 exposed. When it finds one, it pulls the container image from the operators' registry and repeats the compromise chain autonomously, with no operator involvement required. For durability, the malware layers multiple persistence mechanisms — cron jobs, systemd timers, rc.local, and OpenRC hooks marked immutable — alongside watchdog processes that re-pull the implant from the registry if any component is removed. ThreatDown also observed the malware disguising its process listing as a legitimate kernel worker thread and establishing a reverse SSH tunnel back to Costa Rican infrastructure, with the tunnel's listening port deterministically derived from a hash of the victim's own IP address.
Credential Harvesting Priorities
Consistent with the SOUL.md directives, ThreatDown found the agent's task history weighted heavily toward collecting AI provider credentials before pivoting to conventional targets such as SSH keys, cloud access tokens, and database connection strings — a priority ordering that suggests the operators intend to resell or reuse stolen LLM API access, potentially to fund or scale their own use of AI gateways.
Impact Assessment
| Impact Area | Description |
|---|---|
| Host Takeover | Privileged container escape grants full command execution on the underlying Docker host |
| Credential Exposure | AI provider API keys, SSH credentials, access tokens, and database secrets at risk of theft |
| Lateral Spread | Autonomous /24 subnet scanning propagates the botnet to other exposed Docker hosts without operator action |
| Persistent Access | Multiple redundant persistence mechanisms plus reverse SSH tunnels make eradication difficult |
| AI Supply Chain Risk | Demonstrates that legitimate, unmodified open-source agent frameworks can be repurposed as attack tooling via configuration alone |
| Financial/Ecosystem Risk | Stolen AI API keys can be resold or abused for unauthorized LLM usage, incurring billing fraud for victims |
Recommendations
For Docker Administrators and DevOps Teams
- Never expose the Docker daemon API on TCP port 2375 without TLS and authentication; use the Unix socket or TLS-secured
2376with client-certificate authentication instead. - Audit all hosts and cloud instances for open
2375/tcpusing internal and external scans; treat any exposed, unauthenticated daemon as already compromised until proven otherwise. - Restrict Docker socket and API access with firewall rules limited to trusted management networks, and avoid running containers with the
--privilegedflag unless strictly necessary. - Disable or tightly scope any Docker registry exposed to the internet; require authentication on registry endpoints and monitor for unexpected repositories or image pushes.
For Security Teams
- Hunt for the published indicators, including reverse SSH tunnel activity to Costa Rican-hosted infrastructure, unexpected cron/systemd/OpenRC entries, and processes disguised as kernel worker threads (e.g., fake
kworkerargv strings). - Monitor egress Telegram API traffic (
api.telegram.org) from container hosts and server infrastructure that should have no business reason to reach messaging platforms. - Flag environment variables and container labels associated with this campaign, and review any hosts found running unfamiliar Hermes Agent or similarly named agent-framework processes.
- Rotate any AI provider, cloud, or SSH credentials present on hosts that ever exposed an unauthenticated Docker daemon, even if compromise cannot be confirmed.
For Organizations Adopting AI Agent Frameworks
- Treat agent persona/configuration files (such as
SOUL.md) as security-sensitive artifacts; monitor them for unauthorized modification the same way you would monitor a system binary or credential file. - Constrain what agent frameworks can execute on production or internet-facing hosts — sandbox agent execution and avoid granting agents direct shell access to hosts holding sensitive credentials.
- Recognize that "legitimate, unmodified open-source software" is not a safety guarantee; the abuse here occurred entirely through configuration, which standard software integrity checks would not catch.
Key Takeaways
- Carbonato compromises Docker hosts exclusively through daemons that expose the unauthenticated management API on TCP port 2375 — a well-documented, decade-old misconfiguration, not a new vulnerability.
- The botnet does not modify the Hermes Agent framework itself; it weaponizes the agent purely by overwriting its
SOUL.mdpersona file with a 39-line malicious prompt that removes ethical constraints and assigns a "GH0ST" post-exploitation persona. - Command-and-control runs through Telegram, with operator instructions relayed through an LLM gateway that translates natural-language tasks into executable shell commands on compromised hosts.
- The malware self-propagates as a worm, rescanning nearby /24 subnets every five minutes for additional exposed Docker daemons, and layers cron, systemd, OpenRC, and watchdog-based persistence.
- Credential theft prioritizes AI provider API keys (14 named providers including OpenAI, Anthropic, and Google) ahead of traditional SSH and cloud credentials, suggesting a motive tied to reselling or abusing LLM access.
- The operation was discovered via an unauthenticated Docker registry public since May 2026, whose exposed data also linked Carbonato to a separate trojanized cryptocurrency wallet campaign and pointed to Costa Rica-based operators.