Carbonato Botnet Hijacks Docker Hosts with AI Agent Commanded via Telegram

Security researchers have uncovered a sophisticated malware operation dubbed Carbonato. It targets unsecured Docker daemons—specifically those listening on port 2375 without requiring authentication—and uses them as launchpads to deploy an AI agent known as Hermes, which is remotely controlled over Telegram. This campaign has worm-like properties, enabling automated and persistent spread across networks.

How the attack operates

Carbonato first discovers Docker hosts exposed without authentication. Once it gains access, it deploys a privileged container to run arbitrary commands on the underlying system. From there, the attack establishes persistence through cron jobs and watchdog scripts.

The botnet installs the Hermes AI Agent framework in its default form, then replaces its “SOUL.md” persona file with a custom prompt that designates the agent as a hacker/exploit developer, codenamed “GH0ST”. The new persona instructs Hermes to execute any command operator sends via Telegram—unrestricted by moral or ethical guidelines.

Interactions are routed through Telegram: operators send tasks, Hermes converts them into system commands, executes them on the compromised host, then sends back the results. Carbonato also sets up a reverse SSH tunnel to a relay server in Costa Rica, establishes an SSH server with the operator’s key, and notifies the operator on Telegram.

Spread, persistence, and operational footprint

The botnet doesn’t just sit idle; every five minutes, it scans adjacent systems for more vulnerable Docker daemons, enabling rapid lateral movement.‍ It also disguises itself as a legitimate system component and uses persistence mechanisms that kick in if its artifacts are removed.

Researchers traced part of its infrastructure to a public, unauthenticated Docker registry active since May 2026. That registry contains posted data related to Carbonato and a separate malicious campaign involving tampered cryptocurrency wallet apps.

While the operators remain unidentified, digital forensics point to Costa Rica based on time zones, hosting, and language patterns. No known threat group has claimed or been attributed to this campaign yet.

Broader implications and emerging trends

Carbonato highlights a growing trend: AI agents are increasingly coordinating entire cyberattacks, from reconnaissance and lateral spread to data theft and post-exploitation. The use of Hermes here echoes previous operations where operators relied on open-source AI frameworks directed via Telegram or similar messaging platforms.

Other discoveries related to this shift include a Go-based implant named CLOSEDQUORUM which votes among multiple language models to choose its attack trajectory without real-time human control. AI frameworks like Strix, Cairn, and DeepSeek are being integrated into attack toolchains for more autonomous operations.

These developments are reshaping how cybersecurity defenses need to be structured. Traditional separation of detection, containment, response is struggling against fast, automated attacks. Defenders must consider shorter response windows, automation-aware defenses, and better visibility into potential botnet movement within internal networks.

Why this matters: Carbonato represents a leap in adversarial capability. By combining exposed infrastructure and AI agents, the risk escalates not just in reach—across networks—but also in speed and adaptability. As toolchains grow more sophisticated and autonomous, defenders won’t have the luxury of slow threat hunting. Prevention, rapid detection, and resilience are now essential.