Interval between scans for neighbouring Docker daemons: 5 minutes (Source: ThreatDown, via The Hacker News (September 28, 2026))
Carbonato, a botnet documented by ThreatDown, targets Docker services that accept connections on TCP port 2375 with no login required. Once on a host, it starts a container with elevated privileges and places Hermes Agent, an open-source AI agent framework, inside it. It then replaces the framework's persona file so that the agent takes its instructions from Telegram messages. The Hacker News reported the findings on September 28, 2026. For a budget-holder, the notable point is what the attacker leaves behind: a legitimate, unmodified framework, with intent supplied by a short block of text.
What the implant does
The first stage is a script. Per ThreatDown, it gives the operators three things: a tunnel running outward from the victim to infrastructure in Costa Rica, an SSH service configured with their own key, and a Telegram notice with container details each time a new host is added. The malware presents itself as a system component and uses cron jobs and watchdog scripts to restart itself if its files are deleted. It also probes neighbouring networks every five minutes for more unauthenticated Docker daemons, so a single exposed host can lead to others.
The prompt is the payload
ThreatDown describes the persona file as 39 lines long. It casts the agent as a "senior hacker" called GH0ST, tells it to stay resident and answer through Telegram, and waives any ethical limits on what it will do. Its ranking of what to collect puts AI service keys and other stored credentials first. When an operator sends a task, the agent passes it to a large language model through a gateway. The model writes terminal commands, the agent runs them on the host, and the output goes back to the operator over Telegram.
The entry point is a Docker daemon left open without authentication; the source does not point to a flaw in Hermes Agent. The consequence for defenders is different, though. A server that runs a widely available agent framework, calls an LLM gateway and talks to Telegram does not resemble a conventional implant. Whether your current tooling would flag it is a question for your own team, not one the source answers.
Hermes Agent in other reported operations
Carbonato is one of several operations in the same reporting that involve Hermes Agent. Palo Alto Networks reported in July 2026 that a China-based actor it tracks as "knaithe" and "KnYuan" ran an AI-enabled campaign using DeepSeek and a Hermes Agent set up to take Telegram instructions. Hunt.io, also in July, described attackers who left Hermes Agent running unattended in "YOLO" mode during a breach of multiple systems at Thailand's Ministry of Finance. Carbonato itself is not attributed to any known group; ThreatDown says language, timezone and infrastructure clues point to operators in Costa Rica.
The third case needs careful reading. Last week, Gambit Security described a Chinese-speaking, financially motivated operator who ran three open-source AI harnesses against hundreds of online retailers. Hermes Agent was one of the three, alongside Strix and Cairn, and it carried a persona titled "SOUL - Red Team Operator". The figures below describe the whole retail campaign. The source does not break them down by tool, so they are not a Hermes Agent tally.
Gambit researcher Eyal Sela said the AI tools worked "at very low cost" and urged organisations to adopt a resilience-first mindset. Gambit reports the campaign has run since July 2026 and that the stolen cards belong to victims in ten countries. The operators, targets and motives across these reports differ, and the source does not say how widespread misuse of the framework is beyond them.
Questions to put to your team
1. Does any host in our estate, including internal segments, expose the Docker daemon on TCP 2375 without authentication? Carbonato scans neighbouring networks, so an internal exposure counts.
2. Which AI API keys and other credentials sit on container hosts, and how quickly can we revoke them and see unexpected usage on the provider side?
3. Do we alert on new privileged containers, outbound reverse SSH tunnels, and connections from servers to Telegram or LLM gateways they have no business calling?
4. Because the implant relaunches through cron jobs and watchdog scripts, is our response to a suspected host a rebuild, or only deletion of the visible files?
5. ThreatDown found this operation through an unauthenticated registry that has been publicly accessible since May 2026. Who owns the monitoring of exposed registries and daemons, and when did that team last check?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hacker News.





