Carbonato botnet exploits exposed Docker APIs to deploy Hermes AI agent
Malwarebytes' ThreatDown researchers identified a new botnet, Carbonato, that scans for Docker hosts with unauthenticated APIs on port 2375 and hijacks them via privileged containers. The malware installs SSH backdoors, sets up multiple persistence mechanisms, and deploys the Hermes Agent AI framework under an agent named GH0ST to execute operator commands and exfiltrate credentials and API keys via Telegram. The findings came from an unauthenticated Docker registry containing nearly 60 repositories and 4.3GB of data spanning operations from October 2024 to August 2026.
GoKawiil's interpretation of the reporting above, not reported fact.
The use of an AI agent framework to autonomously interpret tasks and execute terminal commands suggests attackers are increasingly automating post-compromise activity rather than relying solely on scripted payloads. Malwarebytes notes Hermes has already been tied to a separate large-scale card-skimming operation, which could indicate the framework is becoming a reusable tool across different criminal campaigns. Exposed Docker daemons remain a known misconfiguration risk, and this case underscores how quickly such exposures can be weaponized into worm-like botnets.
- Carbonato targets Docker hosts with unauthenticated APIs on port 2375 to gain privileged container access.
- It deploys the Hermes Agent AI framework, using an agent named GH0ST, to run operator commands via Telegram.
- Researchers found the campaign details in an exposed Docker registry containing nearly 60 repositories and 4.3GB of data.
YubiKey 5C NFC — This attack thrives on exposed Docker APIs and stolen SSH access, underscoring why hardware-backed authentication matters for server admins and DevOps teams. A YubiKey lets you enforce hardware MFA for SSH and cloud console logins, making stolen credentials far less useful to attackers like those behind Carbonato. It's a simple, durable way to harden the human side of your infrastructure security.
See YubiKey 5C NFC on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: bleepingcomputer.com, 2026-09-24
Published there as: “New Carbonato malware uses AI agents to hijack exposed Docker hosts”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.