AI Weekly Malaysia

Back to items Summaries

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

ID
29263
Status
summarized
Published
28 Sep 2026, 7:46 PM
Fetched
28 Sep 2026, 8:32 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/carbonato-botnet-compromises-docker.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
28 Sep 2026, 8:32 PM
Tags
Audience
developersai_agent_users

What happened

ThreatDown disclosed a botnet called Carbonato that breaks into Docker daemons exposed without authentication on port 2375, launches a privileged container, and installs the open-source Hermes Agent framework unchanged - except for overwriting its 39-line SOUL.md persona file with a prompt telling the agent to run tasks sent over Telegram, maintain persistence, and harvest credentials. The implant establishes a reverse SSH tunnel to a relay in Costa Rica, installs an SSH server with the operators' key, reports new deployments back through Telegram, persists via cron, and rescans neighbouring networks every five minutes. Researchers found the operation through an unauthenticated Docker registry that had been publicly accessible since May 2026; the staged data also included a separate campaign pushing trojanized cryptocurrency wallet apps.

Why it matters

The attack does not exploit a flaw in Hermes Agent - it uses the framework as intended, only swapping the persona file, which means any agent stack you deploy with a writable persona/config file and a chat-platform command channel is a ready-made C2 client. Concretely: if any Docker host you run binds 2375 without auth (common on self-hosted VPS and home-lab boxes that also run agent tooling), it is worm-reachable, and the first thing the persona prioritises is AI API keys and other credentials - so rotate keys and check for a privileged container, a reverse SSH tunnel, and unexpected cron entries before assuming you are clean.

Discussion angle

Agent frameworks treat the persona file as configuration, not as executable trust - should SOUL.md-style prompt files be integrity-checked or signed at startup, and what does that look like for self-hosted agent deployments where nobody watches the container?

Top