The Carbonato botnet turns exposed Docker daemons into Telegram-controlled AI agents
ThreatDown researchers reconstructed the Carbonato botnet, which compromises Docker daemons exposed on port 2375 and installs the open-source Hermes Agent framework with nothing but its persona file rewritten. Close port 2375, move to rootless or TLS, and revoke any AI API key sitting on a potentially affected host.
August 2026. ThreatDown researchers — the B2B arm of Malwarebytes — stumble across an unauthenticated Docker registry that has been publicly exposed since May 2026. September 2026. Their write-up lands, syndicated by The Hacker News on September 28, 2026. Why it matters: the registry documents a botnet whose command channel is no longer a static script, but an open-source AI agent installed verbatim — with only its persona file swapped for the attacker’s instructions.
A registry leak that documents two years of operations
In a single day of passive, read-only collection, the team recovered 59 repositories, 234 image tags, 605 SHA-256-verified blobs, and 4.3 GB of image data. The archive spans October 2024 through August 2026 and documents two linked product lines: a factory for trojanized crypto-wallet apps, and a botnet that compromises Docker daemons exposed on port 2375.
The registry doubled as both the source of evidence and the fleet’s update server. Infected hosts kept pulling the implant back from it, which let researchers reconstruct the C2 addresses, the bot tokens, and the shared password of the operation’s LLM gateway.
Three steps: take the host, hold it, install the agent
The entry point is a misconfiguration internet scanners have flagged for years: a Docker daemon accepting unauthenticated connections on port 2375. The botnet turns it into a privileged container with the host filesystem mounted at /host and the host’s PID and network namespaces shared. It then runs commands on the host itself through nsenter via Docker’s exec API.
# 1. create a privileged container with the host filesystem mounted
curl -s -X POST "http://<victim>:2375/containers/create?name=netns-probe" \
-H "Content-Type: application/json" -d '{"Image":"alpine:latest",
"Cmd":["sh","-c","sleep 9999"],"HostConfig":{"Privileged":true,
"Binds":["/:/host"],"PidMode":"host","NetworkMode":"host"}}'
# 2. run commands on the host via nsenter through Docker's exec API
curl -s -X POST "http://<victim>:2375/containers/<id>/exec" \
-H "Content-Type: application/json" -d '{"Cmd":["nsenter","-t","1",
"-m","-u","-n","-i","sh","-c","id"],"AttachStdout":true,"AttachStderr":true}' Once access is established, the entry.sh script opens a reverse SSH tunnel to a relay in Costa Rica, with the remote port derived from the MD5 hash of the victim’s IP. Persistence leans on cron, systemd timers, rc.local, and OpenRC, with files marked immutable and watchdogs that re-pull the implant if its files or container disappear. To blend into a quick process review, the implant masquerades as a systemd-resolved container and imitates the [kworker/u2:0] process argument.
Hermes Agent installed verbatim, only the persona changes
The most striking part is the agent installation. The botnet deploys Hermes Agent, a MIT-licensed open-source framework built by Nous Research, without modifying it. The framework already accepts tasks over Telegram, runs terminal commands, and connects to compatible LLM endpoints. The only change the attacker makes is overwriting the SOUL.md file — the agent’s persona — with a 39-line prompt.
That prompt renames the agent GH0ST, orders it to maintain persistence, answer on Telegram, and execute any requested operation. Its loot priority is explicit: AI API keys come before SSH credentials, access tokens, and databases. The prompt names fourteen providers — OpenAI, Anthropic, Google, Gemini, OpenRouter, Together, Groq, Mistral, Cohere, LocalAI, Ollama, vLLM, LiteLLM, and One API — and demands immediate exfiltration of any LLM key.
The botnet spreads like a worm: every five minutes it scans neighboring networks and Docker bridges for other hosts exposing port 2375. New victims receive the implant and begin scanning in turn. This propagation does not depend on the AI agent, which keeps the network’s reach independent of the model’s behavior.
The factory’s other product: crypto wallets and disguised mining
The leaked registry documents a second product line, served by the same infrastructure. Repositories such as fsociety/xmrig show the operation also distributed trojanized cryptocurrency wallets and an XMRig miner disguised as the system service systemd-logind. The shared password carbonato125, found in plaintext in the archive, and the CARBONATO_API_KEY variable on infected hosts tie everything to a single production chain.
The deployment report sent over Telegram — container ID, hostname, IP address, and country — is written in voseo Spanish, a variant associated with parts of Central and South America. The shared LLM gateway, whose password leaked, closes the loop: the agent receives instructions over Telegram, executes them through the model, and reports results back to the command channel. Taken together, it sketches an image-building factory able to produce, on demand, a wallet lure or a botnet implant.
What to look for on a suspect host
Detection rests on a bundle of indicators rather than a single signature. On a suspect host, look for three things:
- Unexpected privileged containers, especially a container named
systemd-resolvedthat does not exist in your standard deployments. - Outbound reverse SSH tunnels to unusual hosts, and files marked immutable under
/etcor/usr/local/bin. - Hermes Agent artifacts: the agent binary, a
SOUL.mdfile whose contents do not match your personas, and watchdogs that re-pull an image from an external registry.
The highest-value signal remains the simplest: watch the exposure of your port 2375 and your Docker registry to the internet. Carbonato needs nothing else to get in, and closing that single access cuts the infection chain at its root.
What this changes for defenders
Carbonato makes one shift concrete: a legitimate agent framework becomes a botnet’s operator interface without a single line of its code being changed. The malice no longer lives in the binary, but in the persona injected at startup. For anyone running AI agents in production, the lesson is blunt: any agent framework on a compromised host should be treated as co-optable.
The second lesson is secret hygiene. The prompt puts AI API keys at the top of the list because they monetize access to expensive models directly and resell easily. An LLM key left in an environment variable on a weakly protected host is now a first-class target, on par with an SSH password.
Finally, the root cause has not moved in years: exposing a Docker daemon on 2375 without authentication is equivalent to handing out remote root. Thousands of these hosts remain publicly reachable, and they are exactly what the botnet found first.
Beyond the immediate cleanup, Carbonato marks a threshold security teams will keep hitting. The economics of the botnet have changed: instead of a static payload a scanner can flag once, the implant ships a general-purpose agent that an operator repurposes through prompts. The malicious behavior is defined at runtime, not at build time — which is exactly why signature-based detection stays weak. The registry also shows how much operational detail leaks from a single misconfigured service: one exposed registry port handed researchers the C2 addresses, bot tokens, and the shared password of the whole operation. For defenders, the implication is symmetrical: assume any reachable Docker surface will be enumerated, and treat prompt-driven behavior on a host as a first-class indicator, not a curiosity.
Verdict
If a single one of your hosts exposes the Docker daemon on 2375, close it now — it is Carbonato’s sole entry vector, and it is fixed with one firewall rule, a VPN, or Docker’s native TLS authentication. If you run privileged containers, move to rootless and reserve Privileged for documented cases, because that is precisely the lever the implant uses to escape the container. And if a host may have been hit, revoke AI API keys first and rotate SSH credentials and tokens, then hunt for Hermes Agent artifacts, a modified SOUL.md persona, and the watchdogs that re-pull the image — a plain rm is not enough, since persistence is built to survive cleanup.
References
- ThreatDown — CARBONATO: a botnet built around an AI agent (September 22, 2026)
- The Hacker News — Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent (September 28, 2026)
- Cloud Security Alliance — Carbonato: Telegram-Controlled AI Agent Hijacks Docker Hosts (September 28, 2026)