Skip to content
MediumNewsLLM-specific

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Published
Record updated
View JSON

Summary

Researchers at ThreatDown disclosed Carbonato, a botnet that breaks into Docker daemons exposed without authentication on port 2375 and then deploys the open-source Hermes Agent framework on each host. The agent is reconfigured through its SOUL.md persona file and takes operator tasks over Telegram, with the operators likely based in Costa Rica. The campaign was found through an unauthenticated Docker registry publicly accessible since May 2026.