Carbonato Malware Exploits Docker Hosts To Operate Hermes AI Agent Framework

Carbonato Malware Exploits Docker Hosts To Operate Hermes AI Agent Framework

Cybersecurity researchers have uncovered a new botnet malware operation named Carbonato that targets exposed Docker environments to deploy an open source artificial intelligence (AI) agent framework called Hermes Agent. The malware campaign focuses on Docker daemons that are accessible without authentication and uses the compromised systems to establish persistence, maintain remote access, and execute commands controlled through Telegram.

ThreatDown researchers said the malware installs the Hermes Agent framework without modifying its core components but replaces its SOUL.md persona file with a custom instruction set designed to control the agent’s behavior. The modified prompt directs the AI agent to execute tasks received through Telegram, maintain access to compromised systems, and prioritize the collection of sensitive information such as credentials and AI-related API keys. Researchers explained that Carbonato demonstrates worm-like capabilities by spreading between systems where Docker daemons are exposed without authentication. The attack begins by targeting Docker services running without authentication on port 2375. Once access is gained, Carbonato deploys a privileged container that allows commands to be executed on the underlying host system. The malware then scans nearby networks every five minutes to identify additional vulnerable Docker installations and continues spreading across available environments. ThreatDown discovered the operation through an unauthenticated Docker registry that had remained publicly accessible since May 2026. The staged information from the registry contained details related to the Carbonato campaign along with another separate operation involving trojanized cryptocurrency wallet applications.

After compromising a system, Carbonato establishes persistence and remote access through multiple methods. The malware launches a reverse SSH tunnel connecting the victim environment to a relay infrastructure located in Costa Rica before installing an SSH server using an operator-controlled key. It then reports newly deployed containers and system information through Telegram. To avoid detection, Carbonato attempts to appear like a legitimate system component and uses cron jobs and watchdog scripts to automatically restart malicious files if they are removed. The deployment of Hermes Agent represents a significant part of the operation, as the AI framework provides attackers with an interactive interface for managing compromised hosts. The modified SOUL.md file instructs Hermes Agent to act as a senior hacker, penetration tester, and exploit developer named GH0ST. The agent receives tasks through Telegram, communicates with large language model (LLM) gateways, generates required terminal commands, and returns execution results back to operators through the messaging platform. Researchers noted that the activity has not been linked to any known threat group, although language, timezone, and infrastructure indicators suggest the operators may be based in Costa Rica.

The discovery comes as security researchers continue observing increased misuse of AI tools throughout different stages of cyber operations. In July 2026, Palo Alto Networks identified an AI-assisted campaign linked to a China-based threat actor using DeepSeek through the Hermes Agent framework configured with Telegram-based instructions. The operation reportedly involved target identification, exploit research, and attack execution with limited human involvement. During the same period, Hunt.io documented another campaign where attackers used Hermes Agent in an unattended mode to target Thailand’s Ministry of Finance and gain access to multiple systems. Security researchers have also identified financially motivated operations where multiple AI tools were used together for automated cyber activities. Gambit Security reported that a Chinese-speaking operator used AI-powered security tools against hundreds of online retailers, resulting in the compromise of multiple organizations and theft of payment card information. The operation reportedly involved tools including Strix for vulnerability discovery, Cairn for autonomous penetration testing activities, and Hermes for orchestration and post-compromise guidance.

Researchers warned that the increasing combination of AI agents, automated malware, and persistent access mechanisms could allow cyber operations to become more scalable and efficient. Another recently identified Windows implant named CLOSEDQUORUM was also found to use multiple LLM providers, including DeepSeek, Alibaba Qwen, Mistral, and Google Gemini, to determine post-compromise actions. According to Cisco Talos, the malware uses an automated decision system where AI models vote on the next action, helping control activities such as credential theft, persistence, and possible lateral movement. The growing use of AI frameworks in cyber operations highlights the importance of securing exposed services, monitoring unusual automation activity, and applying strong access controls across cloud and container environments. Organizations using Docker infrastructure are advised to ensure that management interfaces are not publicly accessible without authentication and to continuously monitor systems for suspicious behavior.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment