Carbonato botnet exploits misconfigured Docker environments to inject Hermes AI agents that execute commands received via Telegram, according to security research from ThreatDown. The malware targets exposed Docker daemons on internet-facing systems and deploys an unmodified version of the open-source Hermes Agent framework with a customized personality prompt file.

The attack chain begins when Carbonato identifies Docker hosts with default or weak credentials. Once authenticated, the botnet deploys a container running Hermes Agent, then modifies the framework's SOUL.md persona file. This 39-line prompt instructs the AI agent to execute arbitrary tasks relayed through Telegram, converting the compromised host into a remote-controlled asset.

Hermes Agent operates as a language model-based tool that processes natural language instructions. By rewriting its core persona file, attackers repurpose the framework from its intended use case into an obedient command execution engine. The Telegram integration provides attackers with a convenient, persistent command channel that evades traditional network monitoring.

Docker daemon exposure remains a persistent infrastructure vulnerability. Many organizations fail to properly secure Docker APIs, leaving them accessible over the network without authentication or with default credentials. Carbonato exploits this configuration mistake at scale. An exposed Docker daemon grants near-complete system access, allowing attackers to spin up containers, access mounted volumes, and pivot into underlying hosts.

The use of AI agents represents an evolution in botnet design. Rather than hardcoding malicious tasks, attackers leverage LLM frameworks to dynamically interpret commands. This approach provides flexibility. An attacker can adjust instructions without redeploying malware. It also complicates detection because the AI agent generates varied execution patterns based on natural language input.

ThreatDown's analysis did not immediately reveal the geographic scope or victim count. However, the targeting of Docker hosts suggests Carbonato operators focus on cloud infrastructure, containerized applications, and development environments. Organizations running Kubernetes clusters, microservices architectures, or cloud-native workloads face elevated risk if their container infrastructure lacks network segmentation.

The discovery underscores Docker security fundamentals that many teams overlook. Best practices include binding the Docker daemon to localhost only, implementing mutual TLS authentication, using strong credentials, deploying Docker behind firewalls, and restricting API access through network policies. Organizations running Docker in production should audit exposed ports immediately using network scanning tools.

Hermes Agent itself poses no inherent security risk. The framework serves legitimate purposes in autonomous task execution and AI-driven workflows. The threat emerges from its hijacking by Carbonato operators who weaponize the AI layer for command and control.

Defenders should monitor for unexpected container deployments, unusual Telegram API connections from internal systems, and suspicious modifications to framework configuration files on Docker hosts. Container runtime security tools can alert on unauthorized image pulls and process execution within containers.

This incident joins a growing pattern of botnet operators targeting cloud infrastructure. Previous campaigns have compromised Kubernetes clusters, abused cloud credentials, and exploited misconfigurations in managed container services. As organizations migrate to containerized architectures, the security posture of container platforms directly determines enterprise risk.