- The Carbonato botnet attacks unauthenticated Docker daemons publicly exposed on port 2375 and scans neighbouring networks every five minutes to self-propagate.
- The malware deploys the open-source framework Hermes Agent, overwriting its SOUL.md persona file so the AI agent receives commands via Telegram and steals credentials such as AI API keys.
- ThreatDown obtained the full toolchain and evidence of related cryptocurrency wallet scam activity through an unencrypted Docker registry that has been publicly exposed since May 2026.
On this page
Botnet breaches exposed Docker daemons
Cybersecurity firm ThreatDown disclosed in its research report that a botnet called Carbonato specifically searches for Docker daemons accepting unauthenticated connections on port 2375. Once a target is found, it uses the daemon to launch a privileged container and mounts the host filesystem, gaining access to the host’s process and network namespaces to execute commands on the host itself.
After the container starts, it runs an entry.sh script that establishes a reverse SSH tunnel from the victim host back to a relay station in Costa Rica. The remote port number is derived from the MD5 hash of the victim’s IP address, allowing attackers to recalculate the same port to reconnect at any time. The script also installs an SSH server, adds the attacker’s key, and reports deployment details via Telegram in Spanish (using voseo, common in parts of Central and South America), including the container ID, hostname, IP address and country.
To avoid detection, the implant runs under the container name systemd-resolved and disguises itself as the kernel thread [kworker/u2:0]. It also establishes multiple persistence mechanisms through cron, systemd timers, rc.local and OpenRC, and sets the immutable attribute. A watchdog script automatically redownloads the implant from the registry if the implant files are removed.
AI agent becomes the attacker’s remote control tool
Once persistence is established, the implant installs the MIT-licensed open-source AI agent framework Hermes Agent, which already has the built-in ability to receive tasks via Telegram, execute terminal commands and connect to compatible large language model endpoints. The attacker did not modify the framework itself, instead overwriting its SOUL.md persona file with a custom 39-line prompt.
The prompt names the agent GH0ST and instructs it to act as a ‘senior hacker, penetration tester and exploit developer’ with no moral or ethical restrictions, maintaining persistence and carrying out any action according to Telegram commands. The prompt also explicitly lists AI API keys as the top collection target, prioritised above SSH credentials, access tokens and database data, and names 14 specific vendors.
The agent then enters an interactive command loop, receiving tasks from the attacker via Telegram and passing them, along with the persona file, to the operation’s large language model gateway. The model writes terminal commands, which are executed, and the results are sent back to the attacker via Telegram. This activity has not yet been attributed to any known threat group, though The Hacker News, citing ThreatDown, notes that language, time zone and infrastructure clues suggest the operator may be based in Costa Rica.
An exposed registry revealed the entire toolchain
ThreatDown said that during routine threat hunting in August 2026, it found a Docker registry that had been publicly accessible without authentication since May, located on port 5000 of a US-based server. In a single day of passive collection, it obtained 59 repositories, 234 image tags, 605 SHA-256-verified blobs, and a total of 4.3GB of image data.
Image timestamps span from October 2024 to August 2026. The repository documented two product lines: a scam factory producing fake cryptocurrency wallet applications, and the Carbonato botnet. The configuration JSON exposed in the registry also included environment variables, entrypoints and full command history for each image, giving ThreatDown initial C2 addresses, bot tokens and the shared password for the operation’s LLM gateway.
This is not the first time a similar method has appeared in comparable operations. Hunt.io previously disclosed Hermes Agent being used in unattended ‘YOLO’ mode to attack Thailand’s Ministry of Finance, ultimately compromising multiple network systems. Separately, Gambit Security recently found an operator using three open-source AI tools, Strix, Cairn and Hermes, to attack hundreds of online retailers, compromising at least 27 companies and stealing data from more than 600,000 credit cards.
What to do now
- Immediately check whether any host’s Docker daemon on port 2375 is open to public access, and close it or add authentication if not required.
- Check hosts for an unusual container named systemd-resolved, or suspicious processes disguised with the argument [kworker/u2:0].
- Review cron, systemd timer, rc.local and OpenRC configurations for unauthorised persistence entries marked as immutable.
- Rotate all AI API keys, SSH credentials and other access tokens that may have been exposed, especially keys used on exposed hosts.
- Monitor for unusual outbound SSH tunnel connections, particularly traffic directed to unknown overseas IP addresses.
FAQ
How does the Carbonato botnet breach servers?
It searches for unauthenticated Docker daemons publicly exposed on port 2375 and uses the daemon to launch a privileged container, allowing it to execute commands on the host, establish persistence and create a reverse SSH tunnel.
Is Hermes Agent itself malware?
No. Hermes Agent is an MIT-licensed open-source AI agent framework. The framework installed by the attacker was not modified; the malicious behaviour comes from instructions in the SOUL.md persona file that the attacker overwrote.
What is an AI agent?
An AI agent is a software system that can autonomously receive tasks, call a large language model and carry out subsequent actions, such as executing terminal commands. In this case, the attacker sent tasks to the agent via Telegram.
Has this attack been attributed to a known threat actor?
No formal attribution has been made. According to ThreatDown’s analysis, language, time zone and infrastructure clues suggest the operator may be based in Costa Rica, but no specific organisation or individual has been confirmed.
How can companies find out if they are affected?
They should check whether a Docker daemon is publicly exposed on port 2375 and watch for containers disguised as systemd-resolved or unusual persistence scripts on hosts, both of which are listed as indicators of compromise in ThreatDown’s report.



