Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
- ID
- 29263
- Status
- summarized
- Published
- 28 Sep 2026, 7:46 PM
- Fetched
- 28 Sep 2026, 8:32 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 28 Sep 2026, 8:32 PM
- Tags
- Audience
- developersai_agent_users
What happened
ThreatDown disclosed a botnet called Carbonato that breaks into Docker daemons exposed without authentication on port 2375, launches a privileged container, and installs the open-source Hermes Agent framework unchanged - except for overwriting its 39-line SOUL.md persona file with a prompt telling the agent to run tasks sent over Telegram, maintain persistence, and harvest credentials. The implant establishes a reverse SSH tunnel to a relay in Costa Rica, installs an SSH server with the operators' key, reports new deployments back through Telegram, persists via cron, and rescans neighbouring networks every five minutes. Researchers found the operation through an unauthenticated Docker registry that had been publicly accessible since May 2026; the staged data also included a separate campaign pushing trojanized cryptocurrency wallet apps.
Why it matters
The attack does not exploit a flaw in Hermes Agent - it uses the framework as intended, only swapping the persona file, which means any agent stack you deploy with a writable persona/config file and a chat-platform command channel is a ready-made C2 client. Concretely: if any Docker host you run binds 2375 without auth (common on self-hosted VPS and home-lab boxes that also run agent tooling), it is worm-reachable, and the first thing the persona prioritises is AI API keys and other credentials - so rotate keys and check for a privileged container, a reverse SSH tunnel, and unexpected cron entries before assuming you are clean.
Discussion angle
Agent frameworks treat the persona file as configuration, not as executable trust - should SOUL.md-style prompt files be integrity-checked or signed at startup, and what does that look like for self-hosted agent deployments where nobody watches the container?