A newly discovered botnet named Carbonato exploits Docker containers to deploy an AI agent that receives commands through Telegram and extracts API credentials from compromised systems. Security researchers tracking the threat identified the malware using the open source Hermes Agent AI framework, marking one of the first documented cases of threat actors weaponizing legitimate AI orchestration tools for botnet operations.

The Carbonato botnet targets exposed Docker hosts, which frequently run containerized applications without sufficient authentication controls. Once a Docker daemon becomes compromised, the botnet deploys the Hermes Agent AI framework. This framework allows attackers to issue commands through Telegram channels, creating a command and control infrastructure that bypasses traditional network monitoring. The Hermes framework processes natural language instructions and converts them into executable tasks on the infected Docker host.

The primary objective centers on credential theft. Carbonato systematically searches compromised Docker containers for API keys, authentication tokens, and credentials related to machine learning platforms. These stolen credentials grant attackers direct access to AI service providers, potentially enabling abuse of paid API services, unauthorized model training, or extraction of proprietary data. Docker environments frequently store sensitive credentials in configuration files, environment variables, or mounted volumes. Carbonato exploits this common misconfiguration to harvest these secrets at scale.

Docker's popularity in DevOps and cloud-native environments makes it an attractive attack surface. Many organizations expose Docker APIs without authentication, treating them as trusted internal services. Public cloud instances running Docker often face automated scanning from threat actors seeking low-hanging fruit. Once inside a Docker host, attackers gain the ability to spawn arbitrary containers, access host resources, and pivot to other networked systems.

The use of Hermes Agent AI represents an evolution in botnet tactics. Rather than hardcoding specific commands, the framework allows attackers to issue instructions in natural language via Telegram. This abstraction layer simplifies botnet management and reduces the technical burden on operators. The Telegram integration provides reliable command delivery while maintaining operational security through encrypted channels.

The discovery highlights growing intersection between AI infrastructure and security threats. As organizations increasingly adopt AI frameworks and containerization, threat actors actively target these environments. The reuse of legitimate open source tools like Hermes demonstrates how attackers leverage existing security blindspots. Many organizations monitor for malicious binaries but overlook compromised instances of legitimate software frameworks.

Organizations running Docker should implement strict access controls immediately. Docker API endpoints require authentication with TLS certificates. Network segmentation ensures Docker hosts operate within restricted subnets, isolated from untrusted networks. Credential management tools should replace hardcoded secrets stored in container images or environment files. Container image scanning during build pipelines detects known vulnerabilities before deployment. Runtime monitoring of container behavior identifies unusual API calls or credential access patterns.

Monitoring Telegram traffic from infrastructure endpoints provides an additional detection vector. Organizations should block Telegram at the firewall for non-exempt systems. Audit logs from Docker registries and runtimes reveal suspicious container deployments or modifications. Regular patching of Docker runtime and base container images eliminates known entry points.

The emergence of Carbonato demonstrates that AI frameworks introduce new operational risks alongside their benefits. Security teams must extend monitoring and access controls specifically to AI orchestration tools and container environments.