Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: carbonato (1 article)Clear

Carbonato botnet hijacks exposed Docker hosts to run a Telegram controlled AI agent

ThreatDown detailed Carbonato, a botnet that targets Docker daemons exposed without authentication on port 2375 and deploys the open-source Hermes Agent AI framework. It installs the framework unchanged, then overwrites its SOUL.md persona file with a 39-line prompt directing the agent to execute tasks received over Telegram, maintain persistence, and collect credentials. On each host it launches a privileged container to run commands on the underlying system, then scans neighboring networks every five minutes to spread further, giving it worm-like propagation. Researchers found the operation through an unauthenticated Docker registry publicly accessible since May, whose staged data included details of the botnet and a separate campaign distributing trojanized cryptocurrency wallet apps.

Check
Ensure no Docker daemon is exposed on port 2375 without authentication, restrict daemon access, and hunt hosts for Hermes Agent and rogue privileged containers.
Affected
Hosts running Docker daemons reachable without authentication on port 2375 can be taken over, run a Telegram-controlled AI agent, and be used to spread further.
Fix
Bind the Docker API to localhost or protect it with TLS and authentication, segment container hosts, and alert on unexpected privileged containers.