As organizations increasingly adopt cloud-native infrastructure, the threat landscape continues to evolve in 2026. A striking convergence of traditional cloud misconfigurations and modern artificial intelligence tooling has emerged in the wild. A new botnet malware called Carbonato is actively targeting insecure hosts running unauthenticated Docker daemons, utilizing the compromised infrastructure to deploy the Hermes Agent AI framework. This campaign highlights a critical frontier in ai cybersecurity threats, demonstrating how threat actors weaponize agentic frameworks to streamline post-exploitation tasks, harvest credentials, and execute remote operations via Telegram. It is one vivid example of the broader pattern we trace in AI as both weapon and target in the surge of cyberattacks.
Analyzing Carbonato requires looking beyond sensational headlines about autonomous rogue models. Instead, security teams must examine how adversary-controlled AI agents function as force multipliers in real-world attacks, and how organizations can fortify their containerized environments against these sophisticated intrusions.
Understanding Carbonato and Modern AI Cybersecurity Threats
Discovered by enterprise security researchers at ThreatDown, the Carbonato botnet campaign represents a sophisticated evolution in cloud-native malware. Operating across an unauthenticated Docker registry containing nearly 60 repositories and 4.3 GB of image data, researchers uncovered operational telemetry spanning from October 2024 through August 2026.
Carbonato primarily spreads by scanning for exposed Docker daemon APIs—specifically unsecured endpoints operating on port 2375 without TLS authentication. Once an exposed host is identified, the malware connects directly to the Docker API, instructing the daemon to spin up a privileged container that shatters container isolation and grants root-level access to the underlying host.
This initial foothold serves as a launchpad for persistent access mechanisms. The malware establishes a reverse SSH tunnel, installs a persistent SSH server authorized with the attacker's public keys, and broadcasts successful deployment notifications to a Telegram command-and-control channel. Furthermore, comprehensive persistence scripts establish cron jobs, systemd timers, rc.local hooks, and OpenRC scripts, ensuring the infection survives reboots and routine service restarts.
The Role of Hermes Agent in Agentic Security Incidents
A defining characteristic of the Carbonato campaign is its integration of the Hermes Agent AI framework. Rather than acting as a self-propagating autonomous entity making independent strategic decisions, Hermes serves as an advanced, operator-driven remote access and execution tool.
Within the compromised environment, the malware instantiates an agent designated as “GH0ST,” overriding the default SOUL.md persona configuration with attacker-supplied operational instructions. This integration transforms the local LLM-backed agent into an interactive command loop:
- Task Interpretation: The operator sends natural language or structured task directives via Telegram.
- Execution & Interaction: Hermes interprets the directive, writes necessary terminal commands, and executes them on the victim host.
- Feedback Loop: The agent reads command outputs, evaluates success or failure against its operational goals, and compiles a comprehensive progress report sent back to the operator's Telegram chat.
This agentic capability significantly lowers the technical barrier for attackers, allowing them to rapidly harvest AI API keys, SSH credentials, cloud access tokens, and internal network maps without manually crafting custom shell scripts for every target. Carbonato is not an isolated experiment: when the Langflow AI agent workflow flaw was exploited for root access, CISA issued an emergency mitigation directive, underscoring how exposed agent infrastructure has become a recognized escalation path.
Worm-Like Propagation and Infrastructure Mapping
Carbonato does not rely solely on initial scanning; it features aggressive worm-like propagation capabilities. Once installed on a host, internal scripts automatically initiate network sweeps every five minutes across all interfaces and attached local networks discovered on the compromised machine.
By probing adjacent IP spaces for open Docker daemons or exposed management ports, the malware identifies secondary targets and queues them for automated exploitation. This rapid lateral movement allows localized misconfigurations to escalate quickly into enterprise-wide or cloud-wide security incidents.
The operational telemetry recovered by ThreatDown also revealed connections to adjacent cybercrime campaigns, including distribution vectors targeting counterfeit cryptocurrency wallet applications. This echoes the deceptive distribution techniques documented in nearly 300 fake GitHub repos impersonating legitimate software to deliver malware, and underscores the multi-faceted nature of modern botnets, which monetize compromised compute resources through proxying, cryptomining, and credential harvesting.
A Complete Guide to Securing Containerized Environments: CISA Guidance and Defenses
Mitigating sophisticated threats like Carbonato requires adhering to established Cybersecurity Best Practices and cloud security guidelines from agencies such as CISA and industry leaders like IBM. A comprehensive, defense-in-depth approach is essential to neutralize both container misconfigurations and agentic post-exploitation:
1. Hardening Docker Daemons
- Disable TCP Sockets Without TLS: Never expose the Docker daemon socket (
dockerd -H tcp://0.0.0.0:2375) to unauthenticated networks. If remote management is required, enforce strict mutual TLS (mTLS) authentication and IP whitelisting. - Avoid Privileged Containers: Restrict container capabilities. Running containers in
--privilegedmode eliminates kernel namespace isolation, allowing attackers trivial escalation paths to the host operating system.
2. Monitoring and Detection Engineering
- Behavioral Telemetry: Implement Endpoint Detection and Response (EDR) agents or eBPF-based container monitoring tools to detect unauthorized container creation, unexpected reverse SSH tunnels, and abnormal outbound connections to Telegram API endpoints.
- Credential Auditing: Regularly scan internal repositories, environment variables, and mounted volumes for hardcoded AI API keys, SSH private keys, and cloud credentials that automated malware seeks to harvest.
3. Incident Response and Remediation Tutorial
When responding to an active Carbonato infection, security teams should follow a structured remediation workflow:
- Isolate the Host: Immediately disconnect the compromised Docker host from internal and external networks.
- Preserve Forensic Evidence: Capture container logs, memory dumps, cron configurations, and modified systemd timers before termination.
- Purge Unauthorized Artifacts: Terminate malicious containers, remove rogue SSH authorized keys, and audit all user accounts created during the window of compromise.
- Rotate Secrets: Immediately revoke and rotate any API keys, tokens, or credentials present on the compromised host.
Conclusion
The emergence of Carbonato in 2026 marks a pivotal milestone in ai cybersecurity threats, illustrating how modern threat actors combine legacy cloud vulnerabilities with advanced AI agent frameworks. By turning exposed Docker daemons into launching pads for operator-driven LLM assistants, attackers can execute complex multi-step intrusions with unprecedented efficiency.
As organizations navigate this evolving threat landscape, robust cloud hygiene, strict adherence to CISA hardening guidelines, and proactive monitoring of container boundaries remain our strongest defenses against agentic malware and automated botnets.