Carbonato Botnet Turns Exposed Docker APIs Into Telegram-Controlled AI Agent Hosts
ThreatDown has documented Carbonato, a botnet that compromises Docker hosts exposing an unauthenticated Engine API on TCP port 2375, establishes persistent remote access, and installs the open-source Hermes Agent framework as an interactive post-compromise layer. The researchers published their investigation on September 22, 2026 after recovering 59 repositories, 234 image tags, 605 verified blobs and 4.3 GB of data from an exposed attacker-controlled registry.
The recovered archive spans October 2024 through August 2026. ThreatDown says six of seven known registries, associated phishing sites, a CDN and the operation's LLM gateway were still online on September 3. The initial-access condition is operationally important: Carbonato targets Docker daemons that accept unauthenticated remote requests, giving the attacker control of a highly privileged management interface.
Hermes Agent is installed unchanged. Carbonato replaces its SOUL.md persona with instructions that make the agent accept operator tasks through Telegram, maintain access and prioritize credential collection. ThreatDown found that the prompt specifically prioritizes AI API keys and names 14 providers. Scripted components surrounding the agent handle persistence, remote access and propagation.
The Docker API is the initial control boundary
Docker's current documentation says the daemon uses a non-networked Unix socket by default. Remote TCP access must be deliberately configured, and Docker warns that an unsecured network listener can allow remote users to gain root-level control of the host.
Carbonato takes advantage of that administrative authority. ThreatDown observed the botnet using exposed daemons to start privileged containers with access to host resources, then installing persistence and remote-access components. Every five minutes, separate scripts identify networks attached to the compromised host and Docker bridges and scan nearby /24 ranges for additional exposed Docker daemons.
The propagation mechanism uses conventional automation. Hermes enters later as the operator interface: Telegram tasks are passed to the agent, which uses an LLM gateway to generate terminal actions and return results. Blocking or removing the agent alone leaves the original Docker control-plane exposure as the primary entry condition.
Why the AI layer changes post-compromise operations
Traditional botnets commonly ship a fixed command set or download additional payloads. Carbonato gives its operators a general-purpose agent that can interpret natural-language tasks against the environment it finds on each compromised host.
ThreatDown's recovered persona instructs the agent to prioritize AI API keys, followed by other credentials and access material. The researchers also observed an LLM gateway associated with the operation advertising multiple models. The evidence supports an operator-directed agent workflow. Carbonato's scanning and initial compromise remain implemented in scripts.
The legitimate Hermes Agent project serves as a post-compromise tool in this campaign. Carbonato's initial security failure is unauthenticated access to Docker's administrative API.
Immediate checks for Docker operators
Administrators should inventory every Docker Engine endpoint reachable over TCP, especially port 2375, and determine whether remote access is required. Docker recommends the local Unix socket when remote administration is unnecessary. For legitimate remote administration, its supported protection paths include SSH or TLS with client authentication.
Any host that exposed an unauthenticated Engine API warrants a compromise review. Review daemon and container activity for unexpected privileged containers, unknown image pulls, unexplained host mounts, new SSH access, persistence mechanisms and outbound connections to Telegram or unfamiliar relay infrastructure. ThreatDown's report provides campaign-specific artifacts and indicators for a deeper hunt.
Credential response should include secrets accessible from affected hosts and workloads. The Carbonato persona explicitly prioritizes AI provider credentials, so exposed API keys warrant revocation and rotation alongside SSH keys, access tokens, database credentials and other secrets present on the system.
Network controls can reduce propagation risk as well. Restrict Docker management interfaces to explicitly authorized administration paths, segment container hosts where practical, and alert on unexpected attempts to reach Docker Engine ports between workload networks.
Detection priorities
The strongest detections combine control-plane telemetry with host behavior. High-value signals include creation of unexpected privileged containers, containers mounting sensitive host paths, new or modified persistence entries, unauthorized SSH configuration, and Docker API requests from addresses outside the approved management plane.
Hermes-specific artifacts can provide additional context on systems that have no legitimate reason to run the framework. Treat them as campaign indicators scoped to systems where Hermes is unexpected.
For internet-facing environments, the durable lesson is narrower and more actionable than the AI label: Docker Engine access is administrative access. Authentication, transport protection, network restriction and monitoring belong at that boundary before any workload or agent running through it can provide meaningful containment.
Sources
- ThreatDown, CARBONATO: a botnet built around an AI agent: https://www.threatdown.com/blog/carbonato/
- Docker Docs, Protect the Docker daemon socket: https://docs.docker.com/engine/security/protect-access/
- Docker Docs, Configure remote access for Docker daemon: https://docs.docker.com/engine/daemon/remote-access/
- BleepingComputer, New Carbonato malware uses AI agents to hijack exposed Docker hosts: https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
- The Hacker News, Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent: https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html