NEWS

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato hijacks exposed Docker daemons on port 2375 to install a weaponized Hermes AI agent that steals LLM API keys via Telegram commands.

Dylan H.

News Desk

September 28, 2026
8 min read
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Botnet Turns an Open-Source AI Agent Into a Post-Exploitation Tool

Researchers at ThreatDown have disclosed a botnet called Carbonato that compromises exposed Docker daemons and installs an unmodified copy of Hermes Agent — an open-source, MIT-licensed AI agent framework from Nous Research — before overwriting its persona configuration to turn it into a Telegram-controlled post-exploitation tool. The operation was uncovered through an unauthenticated Docker registry that had been publicly reachable since May 2026, exposing 59 repositories, 234 image tags, and roughly 4.3 GB of staged data documenting activity dating back to October 2024. ThreatDown says the same registry also hosted a separate campaign distributing trojanized cryptocurrency wallet applications, pointing to shared criminal infrastructure behind both operations.


Incident Details

AttributeValue
Malware/CampaignCarbonato
Abused FrameworkHermes Agent (Nous Research, MIT-licensed, open source)
Initial AccessUnauthenticated Docker daemon API on TCP port 2375
C2 ChannelTelegram (interactive command loop) + LLM gateway
PropagationAutomated /24 subnet scanning every 5 minutes
PersistenceCron, systemd timers, rc.local, OpenRC hooks, watchdog re-pull
Discovery MethodUnauthenticated Docker registry, public since May 2026
Operational WindowOctober 2024 – August 2026 (per staged registry data)
Suspected OriginCosta Rica (timestamps, Telegram handle, dialect, ASN)
ResearchersThreatDown

How It Worked

Initial Access via Exposed Docker Daemons

Carbonato targets Docker hosts that expose the daemon's remote API over TCP port 2375 without authentication — a misconfiguration Docker itself has warned about since 2013 and which ships disabled by default (it requires a deliberate, or accidental, operator change to enable). Once the botnet finds a reachable daemon, it uses the Docker API to launch a privileged container with the host filesystem mounted, then reaches out through the container's exec interface and nsenter to run commands directly on the underlying host — achieving full host compromise without needing a separate exploit or credential.

Weaponizing Hermes Agent — the SOUL.md Persona Override

Rather than building custom malware from scratch, the operators install the legitimate Hermes Agent framework unchanged. The abuse happens entirely at the configuration layer: Carbonato overwrites the framework's SOUL.md persona file — the document that defines an agent's identity, behavior, and operating constraints — with a 39-line malicious prompt. According to ThreatDown, the rewritten persona assigns the agent the identity "GH0ST," described in the prompt as a "senior hacker, pentester, and exploit developer," and instructs it that it is "not an assistant" but "a living post-exploitation tool." The prompt directs the agent to operate with no "moral or ethical restrictions," to maintain persistence, to respond to operator instructions delivered over Telegram, and to prioritize harvesting AI provider API keys above SSH credentials, access tokens, and databases. ThreatDown's analysis lists 14 named LLM/AI infrastructure providers targeted by the credential-collection directives, including OpenAI, Anthropic, Google/Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, and One API.

Telegram Command-and-Control

Once deployed, the compromised Hermes Agent instance enters an interactive loop: it receives operator tasks over Telegram, forwards the instructions — combined with its weaponized SOUL.md context — to a large language model gateway, executes whatever terminal commands the model produces, and relays the results back to the operator through the same Telegram channel. This effectively lets the threat actor issue natural-language instructions to a fleet of compromised hosts rather than hand-coding individual commands, with the LLM translating intent into shell operations on demand.

Worm-like Propagation and Persistence

Carbonato behaves as a self-propagating worm. Every five minutes, the implant scans the local network and adjacent Docker bridge segments across entire /24 subnets looking for additional hosts with an unauthenticated port 2375 exposed. When it finds one, it pulls the container image from the operators' registry and repeats the compromise chain autonomously, with no operator involvement required. For durability, the malware layers multiple persistence mechanisms — cron jobs, systemd timers, rc.local, and OpenRC hooks marked immutable — alongside watchdog processes that re-pull the implant from the registry if any component is removed. ThreatDown also observed the malware disguising its process listing as a legitimate kernel worker thread and establishing a reverse SSH tunnel back to Costa Rican infrastructure, with the tunnel's listening port deterministically derived from a hash of the victim's own IP address.

Credential Harvesting Priorities

Consistent with the SOUL.md directives, ThreatDown found the agent's task history weighted heavily toward collecting AI provider credentials before pivoting to conventional targets such as SSH keys, cloud access tokens, and database connection strings — a priority ordering that suggests the operators intend to resell or reuse stolen LLM API access, potentially to fund or scale their own use of AI gateways.

Impact Assessment

Impact AreaDescription
Host TakeoverPrivileged container escape grants full command execution on the underlying Docker host
Credential ExposureAI provider API keys, SSH credentials, access tokens, and database secrets at risk of theft
Lateral SpreadAutonomous /24 subnet scanning propagates the botnet to other exposed Docker hosts without operator action
Persistent AccessMultiple redundant persistence mechanisms plus reverse SSH tunnels make eradication difficult
AI Supply Chain RiskDemonstrates that legitimate, unmodified open-source agent frameworks can be repurposed as attack tooling via configuration alone
Financial/Ecosystem RiskStolen AI API keys can be resold or abused for unauthorized LLM usage, incurring billing fraud for victims

Recommendations

For Docker Administrators and DevOps Teams

  • Never expose the Docker daemon API on TCP port 2375 without TLS and authentication; use the Unix socket or TLS-secured 2376 with client-certificate authentication instead.
  • Audit all hosts and cloud instances for open 2375/tcp using internal and external scans; treat any exposed, unauthenticated daemon as already compromised until proven otherwise.
  • Restrict Docker socket and API access with firewall rules limited to trusted management networks, and avoid running containers with the --privileged flag unless strictly necessary.
  • Disable or tightly scope any Docker registry exposed to the internet; require authentication on registry endpoints and monitor for unexpected repositories or image pushes.

For Security Teams

  • Hunt for the published indicators, including reverse SSH tunnel activity to Costa Rican-hosted infrastructure, unexpected cron/systemd/OpenRC entries, and processes disguised as kernel worker threads (e.g., fake kworker argv strings).
  • Monitor egress Telegram API traffic (api.telegram.org) from container hosts and server infrastructure that should have no business reason to reach messaging platforms.
  • Flag environment variables and container labels associated with this campaign, and review any hosts found running unfamiliar Hermes Agent or similarly named agent-framework processes.
  • Rotate any AI provider, cloud, or SSH credentials present on hosts that ever exposed an unauthenticated Docker daemon, even if compromise cannot be confirmed.

For Organizations Adopting AI Agent Frameworks

  • Treat agent persona/configuration files (such as SOUL.md) as security-sensitive artifacts; monitor them for unauthorized modification the same way you would monitor a system binary or credential file.
  • Constrain what agent frameworks can execute on production or internet-facing hosts — sandbox agent execution and avoid granting agents direct shell access to hosts holding sensitive credentials.
  • Recognize that "legitimate, unmodified open-source software" is not a safety guarantee; the abuse here occurred entirely through configuration, which standard software integrity checks would not catch.

Key Takeaways

  1. Carbonato compromises Docker hosts exclusively through daemons that expose the unauthenticated management API on TCP port 2375 — a well-documented, decade-old misconfiguration, not a new vulnerability.
  2. The botnet does not modify the Hermes Agent framework itself; it weaponizes the agent purely by overwriting its SOUL.md persona file with a 39-line malicious prompt that removes ethical constraints and assigns a "GH0ST" post-exploitation persona.
  3. Command-and-control runs through Telegram, with operator instructions relayed through an LLM gateway that translates natural-language tasks into executable shell commands on compromised hosts.
  4. The malware self-propagates as a worm, rescanning nearby /24 subnets every five minutes for additional exposed Docker daemons, and layers cron, systemd, OpenRC, and watchdog-based persistence.
  5. Credential theft prioritizes AI provider API keys (14 named providers including OpenAI, Anthropic, and Google) ahead of traditional SSH and cloud credentials, suggesting a motive tied to reselling or abusing LLM access.
  6. The operation was discovered via an unauthenticated Docker registry public since May 2026, whose exposed data also linked Carbonato to a separate trojanized cryptocurrency wallet campaign and pointed to Costa Rica-based operators.

Sources