
Carbonato Botnet Exploits Unauthenticated Docker Daemons for Hermes AI Telegram Control
Carbonato infects unauthenticated Docker instances to run a Telegram-controlled Hermes AI agent for credential theft and spread. Public registry data since May 2026 and cross-referenced Hermes operations reveal non-state operators in Costa Rica. The combination of worm behavior and LLM tasking marks a shift toward automated persistence on container infrastructure.
The botnet scans neighboring networks every five minutes after initial compromise, launching privileged containers to execute commands, install reverse SSH tunnels, and drop cron-based watchdog scripts. Evidence from a public Docker registry active since May 2026 includes staged botnet artifacts and a parallel trojanized crypto wallet campaign, confirming worm-like propagation without authentication.
Palo Alto Networks documented Hermes Agent use by China-linked actors knaithe and KnYuan in July 2026 for DeepSeek-driven enumeration and exploits. Hunt.io separately traced unattended Hermes deployments against Thailand's Ministry of Finance, where the same Telegram loop enabled autonomous lateral movement. Carbonato's Costa Rica infrastructure and language markers diverge from those clusters.
Operators prioritize AI-driven task execution without ethical constraints, using the agent to name API keys first. This pattern signals accelerating automation of access maintenance across exposed container hosts. Next indicators will likely appear in new registry snapshots or SSH key reuse across additional regions.
Carbonato operators: Registry will yield evidence of 150+ additional Docker hosts compromised by 15 November 2026.
Sources (3)
- [1]ThreatDown Carbonato Disclosure(https://www.threatdown.com/research/carbonato-botnet)
- [2]Palo Alto Unit 42 Knaithe Report(https://unit42.paloaltonetworks.com/knaithe-ai-hacking)
- [3]Hunt.io Hermes Thailand Operation(https://hunt.io/blog/hermes-agent-mof-breach)