Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Carbonato botnet plants Hermes AI agent on exposed Docker hosts, ThreatDown says

Security firm ThreatDown found a botnet that installs an off-the-shelf AI agent on hijacked Docker servers and puts AI API keys first on its theft list.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1ThreatDown says Carbonato hijacks Docker daemons left open without authentication on port 2375 and spreads every five minutes.
  • 2The botnet installs the open-source Hermes Agent unchanged; a 39-line persona file turns it into a Telegram-steered attacker.
  • 3The agent's instructions rank AI API keys from 14 providers ahead of SSH credentials, so key inventories and rotation matter.

The news

The Carbonato botnet breaks into Docker servers left open to the internet and installs an open-source AI agent that its operators control through Telegram, security firm ThreatDown said in a report published September 22, 2026.

According to ThreatDown, the botnet goes after Docker daemons, the background service that runs containers, when they are exposed without authentication on port 2375. Once inside, it starts a privileged container with the host's file system mounted, which lets it run commands on the underlying machine. Every five minutes it scans the networks attached to the host and its Docker bridges for more exposed daemons.

The payload is Hermes Agent, an MIT-licensed open-source agent framework from Nous Research that can already take tasks over Telegram, run terminal commands and connect to large language model (LLM) endpoints. ThreatDown said the botnet installs the framework unchanged and overwrites a single persona file, SOUL.md, with a 39-line prompt that names the agent “GH0ST.” An operator sends a task in Telegram, the agent passes it to the operation's LLM gateway, and the model turns it into shell commands, checks the results and chooses the next step.

The prompt tells the agent to keep its foothold, follow Telegram instructions and collect credentials. ThreatDown said it ranks AI API keys from 14 named providers, including OpenAI, Anthropic and Google, ahead of SSH credentials. To survive cleanup, the kit installs hooks through cron, systemd timers, rc.local and OpenRC, marks its files immutable, and runs watchdog processes that pull the implant again if its files or container disappear. The Hacker News, which reported the findings on September 28, said a shell script opens a reverse SSH tunnel from each victim to a relay in Costa Rica.

ThreatDown said it uncovered the operation in August 2026, when it found an unauthenticated Docker registry that had been publicly exposed since May. In one day of read-only collection it recovered 59 repositories, 234 image tags and 4.3 GB of image data spanning October 2024 through August 2026. The archive also documented a second line of business, a factory distributing trojanized cryptocurrency wallet apps, and it contained references to the XMRig cryptocurrency miner.

ThreatDown did not say how many hosts are infected and did not tie Carbonato to a known threat group. It said language, time zone and infrastructure clues point to operators in Costa Rica, including a Telegram handle, “Carbo506,” that contains the country's +506 calling code.

The numbers

Docker API port targeted
2375 (unauthenticated)
Propagation scan interval
Every 5 minutes
Malicious persona prompt
39 lines
AI providers whose keys are targeted
14
Recovered from exposed registry
59 repositories, 234 image tags, 4.3 GB
Period covered by the archive
October 2024 to August 2026

Why CEOs should care

For CISOs and infrastructure leaders, an exposed Docker API used to mean a hijacked server mining cryptocurrency on the company's power bill. Carbonato shows the same mistake can now hand an outsider a tool that takes plain-language orders, runs commands and looks for secrets. ThreatDown's first recommendation is simple: do not expose the Docker daemon API to the network, and require authentication on container registries. Security teams can also hunt for SOUL.md files containing “GH0ST,” .env files carrying a CARBONATO_API_KEY variable, and unexplained Telegram traffic leaving servers.

For CFOs and anyone buying AI services, the target list matters. The agent's instructions put AI API keys first, and ThreatDown advises companies to “treat AI API keys like bank credentials.” That means knowing where every key lives, rotating keys on a schedule and watching usage for spikes. A useful question for engineering leaders: who owns the inventory of model provider keys across teams, and would anyone notice if one started running jobs at 3 a.m.?

Boards should ask a narrower question than “are we patched?” Carbonato relies on a configuration error, not a software flaw. The right check is whether management can name every internet-facing container host, including test and shadow projects, and show that each one requires authentication.

The bigger picture

Attackers have long reused legitimate administration tools to blend in. Carbonato applies that approach to AI agents: according to ThreatDown, the framework itself is untouched and the malicious intent sits in one plain-text instruction file. In our assessment, that makes the operation harder to spot with tools that look for known malicious code, and it lets operators change their goals by editing a prompt rather than rewriting software. As more companies deploy agent frameworks for legitimate work, defenders will need to watch what agents are told to do, not only which programs are installed.

What’s next

ThreatDown published indicators of compromise, including a command-and-control hub at 45.79.183.61 on Linode and a reverse-tunnel endpoint at 190.211.124.187 on the Costa Rican network AS262145, which security teams can add to their monitoring. Watch for follow-up research that measures how many hosts are infected, and for any guidance from Nous Research on detecting misuse of Hermes Agent.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

CarbonatoThreatDownDockerHermes AgentAI agents

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.