The news
The Carbonato botnet breaks into Docker servers left open to the internet and installs an open-source AI agent that its operators control through Telegram, security firm ThreatDown said in a report published September 22, 2026.
According to ThreatDown, the botnet goes after Docker daemons, the background service that runs containers, when they are exposed without authentication on port 2375. Once inside, it starts a privileged container with the host's file system mounted, which lets it run commands on the underlying machine. Every five minutes it scans the networks attached to the host and its Docker bridges for more exposed daemons.
The payload is Hermes Agent, an MIT-licensed open-source agent framework from Nous Research that can already take tasks over Telegram, run terminal commands and connect to large language model (LLM) endpoints. ThreatDown said the botnet installs the framework unchanged and overwrites a single persona file, SOUL.md, with a 39-line prompt that names the agent “GH0ST.” An operator sends a task in Telegram, the agent passes it to the operation's LLM gateway, and the model turns it into shell commands, checks the results and chooses the next step.
The prompt tells the agent to keep its foothold, follow Telegram instructions and collect credentials. ThreatDown said it ranks AI API keys from 14 named providers, including OpenAI, Anthropic and Google, ahead of SSH credentials. To survive cleanup, the kit installs hooks through cron, systemd timers, rc.local and OpenRC, marks its files immutable, and runs watchdog processes that pull the implant again if its files or container disappear. The Hacker News, which reported the findings on September 28, said a shell script opens a reverse SSH tunnel from each victim to a relay in Costa Rica.
ThreatDown said it uncovered the operation in August 2026, when it found an unauthenticated Docker registry that had been publicly exposed since May. In one day of read-only collection it recovered 59 repositories, 234 image tags and 4.3 GB of image data spanning October 2024 through August 2026. The archive also documented a second line of business, a factory distributing trojanized cryptocurrency wallet apps, and it contained references to the XMRig cryptocurrency miner.
ThreatDown did not say how many hosts are infected and did not tie Carbonato to a known threat group. It said language, time zone and infrastructure clues point to operators in Costa Rica, including a Telegram handle, “Carbo506,” that contains the country's +506 calling code.
The numbers
- Docker API port targeted
- 2375 (unauthenticated)
- Propagation scan interval
- Every 5 minutes
- Malicious persona prompt
- 39 lines
- AI providers whose keys are targeted
- 14
- Recovered from exposed registry
- 59 repositories, 234 image tags, 4.3 GB
- Period covered by the archive
- October 2024 to August 2026
Why CEOs should care
For CISOs and infrastructure leaders, an exposed Docker API used to mean a hijacked server mining cryptocurrency on the company's power bill. Carbonato shows the same mistake can now hand an outsider a tool that takes plain-language orders, runs commands and looks for secrets. ThreatDown's first recommendation is simple: do not expose the Docker daemon API to the network, and require authentication on container registries. Security teams can also hunt for SOUL.md files containing “GH0ST,” .env files carrying a CARBONATO_API_KEY variable, and unexplained Telegram traffic leaving servers.
For CFOs and anyone buying AI services, the target list matters. The agent's instructions put AI API keys first, and ThreatDown advises companies to “treat AI API keys like bank credentials.” That means knowing where every key lives, rotating keys on a schedule and watching usage for spikes. A useful question for engineering leaders: who owns the inventory of model provider keys across teams, and would anyone notice if one started running jobs at 3 a.m.?
Boards should ask a narrower question than “are we patched?” Carbonato relies on a configuration error, not a software flaw. The right check is whether management can name every internet-facing container host, including test and shadow projects, and show that each one requires authentication.
The bigger picture
Attackers have long reused legitimate administration tools to blend in. Carbonato applies that approach to AI agents: according to ThreatDown, the framework itself is untouched and the malicious intent sits in one plain-text instruction file. In our assessment, that makes the operation harder to spot with tools that look for known malicious code, and it lets operators change their goals by editing a prompt rather than rewriting software. As more companies deploy agent frameworks for legitimate work, defenders will need to watch what agents are told to do, not only which programs are installed.
What’s next
ThreatDown published indicators of compromise, including a command-and-control hub at 45.79.183.61 on Linode and a reverse-tunnel endpoint at 190.211.124.187 on the Costa Rican network AS262145, which security teams can add to their monitoring. Watch for follow-up research that measures how many hosts are infected, and for any guidance from Nous Research on detecting misuse of Hermes Agent.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error







