MediumNewsLLM-specific
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
- Published
- Record updated
Summary
Researchers at ThreatDown disclosed Carbonato, a botnet that breaks into Docker daemons exposed without authentication on port 2375 and then deploys the open-source Hermes Agent framework on each host. The agent is reconfigured through its SOUL.md persona file and takes operator tasks over Telegram, with the operators likely based in Costa Rica. The campaign was found through an unauthenticated Docker registry publicly accessible since May 2026.
Topics
Related items
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database